Heap-based Buffer Overflow vulnerability in Adobe Acrobat DC
ID: 4a7e1609-b0d2-57da-a364-e665223c67e9
STIX ID: report--4a7e1609-b0d2-57da-a364-e665223c67e9
Feed Name: Zscaler Security Research Blog
This Zscaler ThreatLabz report analyzes CVE-2021-44708, a heap-based buffer overflow in the Solid Framework component used by Adobe Acrobat/Reader and Foxit PDF Editor that can lead to arbitrary code execution when a user opens a malicious PDF and triggers a color-conversion path. The report provides a minimal PoC, step-by-step debug and disassembly analysis showing how malformed operands to the 'scn' operator cause out-of-bounds CLUT indexing during CMYK-to-RGB conversion, lists affected product versions, test environment details, and recommends updating affected software and using advanced threat protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
