VID |
50367 |
Severity |
40 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
The version of Adobe Reader installed on the remote Windows host is a version prior to 17.011.30207, 20.004.30020, or 21.011.20039. It is, therefore, affected by multiple vulnerabilities.
- Use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. (CVE-2021-44701)
- Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a victim must visit an attacker controlled web page. (CVE-2021-44702)
- Stack buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. (CVE-2021-44703)
- Use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. (CVE-2021-44704, CVE-2021-44705)
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these conditions will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: https://cwe.mitre.org/data/definitions/20.html https://cwe.mitre.org/data/definitions/121.html https://cwe.mitre.org/data/definitions/122.html https://cwe.mitre.org/data/definitions/125.html https://cwe.mitre.org/data/definitions/190.html https://cwe.mitre.org/data/definitions/284.html https://cwe.mitre.org/data/definitions/416.html https://cwe.mitre.org/data/definitions/476.html https://cwe.mitre.org/data/definitions/657.html https://cwe.mitre.org/data/definitions/787.html https://cwe.mitre.org/data/definitions/788.html https://cwe.mitre.org/data/definitions/824.html https://helpx.adobe.com/security/products/acrobat/apsb22-01.html
* Platforms Affected: Adobe Reader versions prior to 17.011.30207 Microsoft Windows Any version Linux Any version |
Recommendation |
Upgrade to the latest version of Adobe Reader (17.011.30207 or later), as described in the Adobe Security bulletin at https://helpx.adobe.com/security/products/acrobat/apsb22-01.html |
Related URL |
CVE-2021-44701,CVE-2021-44702,CVE-2021-44703,CVE-2021-44704,CVE-2021-44705,CVE-2021-44706,CVE-2021-44707,CVE-2021-44708,CVE-2021-44709 (CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|