Adobe Acrobat DC JavaScript submitForm URL Buffer Overflow

Strike ID:
E20-1481s
CVSS:
7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2020

Description

A buffer overflow vulnerability exists in Adobe Acrobat Pro DC. Specifically the vulnerability exists within the WebPDF.api. Type confusion occurs when an invalid Unicode string is created as an ANSI string from a source Unicode string. By enticing a victim to open a crafted pdf document an attacker may cause a denial of service or information disclosure on the machine. It may also be possible to execute arbitrary code on a victim's system.

CVE

References