Adobe Acrobat Reader DC WM_SETFOCUS Use After Free Memory Corruption

Strike ID:
E21-cbgf1
CVSS:
7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
t
Variants:
108
Year:
2021

Description

This strike exploits a memory corruption vulnerability in Adobe Acrobat Reader DC. The vulnerability occurs due to incorrect handling of text objects while processing WM_SETFOCUS message. An object might be destroyed and re-accessed, leading to use-after-free condition. An attacker could exploit this vulnerability by enticing a user to open a maliciously crafted PDF document with the vulnerable software, potentially executing arbitrary code.

CVE

References