This application requires Javascript for optimal performance.

Adobe.Acrobat.GetAnnots.Code.Execution

Release Date

May 04, 2009

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a vulnerability in Adobe Reader and Adobe Acrobat.

The vulnerability is caused by an error when the affected software handles a malicious JavaScript. It allows a remote attacker to execute arbitrary code via sending a crafted PDF file.

Affected Products

Adobe Reader and Adobe Acrobat 9.1, 8.1.4, and 7.1.1 and earlier versions

Recommended Actions

Currently we are not aware of any patches supplied by the vendor for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-1492

Reference/s

http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html
http://www.securityfocus.com/bid/34736 (BugTraq)
http://milw0rm.com/exploits/8569

Reference: VID-17413