Korean
<< Back
VID 50000
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description A version of Adobe Acrobat reader which is older than 8.3 or 9.4.5 or 10.1 been installed on the host.
Such versions are reportedly affected by multiple vulnerabilities :
- Multiple buffer overflow vulnerabilities exist that could lead to code execution. (CVE-2011-2094, CVE-2011-2095, CVE-2011-2097)

- A heap overflow vulnerability exists that could lead to code execution. (CVE-2011-2096)

- Multiple memory corruption vulnerabilities exist that could lead to code execution. (CVE-2011-2098, CVE-2011-2099, CVE-2011-2103)

- Multiple memory corruption vulnerabilities exist that could cause the application to crash. (CVE-2011-2104, CVE-2011-2105)

- Multiple memory corruption vulnerabilities exist that could lead to code execution. (CVE-2011-0563)

- A DLL loading vulnerability exists that could lead to code execution. (CVE-2011-2100)

- A cross document script execution vulnerability exists that could lead to code execution. (CVE-2011-2101)

- A security bypass vulnerability exists that could lead to bypassing security restrictions. (CVE-2011-2102)

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://www.zerodayinitiative.com/advisories/ZDI-11-218
http://www.zerodayinitiative.com/advisories/ZDI-11-219
http://www.adobe.com/support/security/bulletins/apsb11-16.html

* Platforms Affected:
Adobe Acrobat Reader versions prior to 8.3 or 9.4.5 or 10.1
Microsoft Windows Any version
Linux Any version
Recommendation Upgrade to the latest version of Adobe Reader(8.3/9.4.5/10.1 or later), as described in the Adobe Security bulletin at http://www.adobe.com/support/security/advisories/apsa11-16.html
Related URL CVE-2011-2094,CVE-2011-2095,CVE-2011-2096,CVE-2011-2097,CVE-2011-2098,CVE-2011-2099,CVE-2011-2100,CVE-2011-2101 (CVE)
Related URL 48240,48242,48243,48244,48245,48246,48247,48248,48251,48252,48253,48255 (SecurityFocus)
Related URL (ISS)