CVE-2010-1240
84Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actepss 74%
de la publicación al arma0 días
Publicada en NVD5 abr
1ª PoC31 mar
metasploit29 mar
VulnCheck+2233d
probabilidad de explotación
74%top 1% de las CVE
explotación observada
síVulnCheck
9 exploit(s) público(s)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary local program that was specified in a PDF document, as demonstrated by a text field that claims that the Open button will enable the user to read an encrypted message.
Productos afectados
n/a · n/aPoCs públicas encontradas — 9✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/16671exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/16682exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/11987githubgithub.com/Jasmoon99/Embedded-PDF★ 71githubgithub.com/omarothmann/Embedded-Backdoor-Connection★ 8githubgithub.com/asepsaepdin/CVE-2010-1240★ 1githubgithub.com/ocfagb/hacktivity-vulns-exploits-lab★ 0githubgithub.com/12345qwert123456/CVE-2010-1240★ 0vulncheckvulncheck.com/xdb/b845ddfb9e40no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://blog.didierstevens.com/2010/03/29/escape-from-pdf/http://blog.didierstevens.com/2010/06/29/quickpost-no-escape-from-pdf/http://lists.immunitysec.com/pipermail/dailydave/2010-April/006075.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7466http://www.adobe.com/support/security/bulletins/apsb10-15.htmlhttp://www.securitytracker.com/id?1024159http://www.us-cert.gov/cas/techalerts/TA10-231A.htmlhttp://www.vupen.com/english/advisories/2010/1636