Network Security, Vulnerability Management

Patched Acrobat Reader heap overflow flaw could result in remote code execution

One of the vulnerabilities patched in Adobe Systems' most recent software update was a flaw in the JPEG decoder and parser of Adobe Acrobat Reader, which could have been exploited to execute code remotely, Cisco's Talos threat intelligence division

According to a Talos security advisory posted last week, the specific flaw is a use-of-uninitialized-memory vulnerability that results in a heap-based buffer overflow, which can in turn be abused using a specially crafted PDF file with an embedded JPEG. Users can fall victim to the bug by visiting a malicious web page or opening a malicious email attachment.

Patched earlier this month, the bug in the JPEG decoder was discovered by Talos researcher Aleksandar Nikolic. Officially designated as CVE-2017-2971, the vulnerability "can result in the use of two 4 byte integer values which are previously uninitialized," the advisory explains. "The use of these two uninitialized variables leads to further process corruptions..."

As with previous Reader exploits, "the heap can be groomed in a specific way so that the uninitialized memory falls under attackers' control, which could then end up controlling the heap buffer overflow size directly, Talos continues in its advisory. "With further heap layout control this can lead to successful exploitation and remote code execution." 

Bradley Barth

As director of multimedia content strategy at CyberRisk Alliance, Bradley Barth develops content for online conferences, webcasts, podcasts video/multimedia projects — often serving as moderator or host. For nearly six years, he wrote and reported for SC Media as deputy editor and, before that, senior reporter. He was previously a program executive with the tech-focused PR firm Voxus. Past journalistic experience includes stints as business editor at Executive Technology, a staff writer at New York Sportscene and a freelance journalist covering travel and entertainment. In his spare time, Bradley also writes screenplays.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms and Conditions and Privacy Policy.