Adobe Acrobat < 10.1.12 / 11.0.09 Multiple Vulnerabilities (APSB14-20)

critical Nessus Plugin ID 77711

Synopsis

The version of Adobe Acrobat on the remote Windows host is affected by multiple vulnerabilities.

Description

The version of Adobe Acrobat installed on the remote host is a version prior to 10.1.12 / 11.0.09. It is, therefore, affected by the following vulnerabilities :

- A use-after-free error exists that allows arbitrary code execution. (CVE-2014-0560)

- A heap-based buffer overflow exists that allows arbitrary code execution. (CVE-2014-0561, CVE-2014-0567)

- A memory corruption error exists that allows denial of service attacks. (CVE-2014-0563)

- Memory corruption errors exist that allows arbitrary code execution. (CVE-2014-0565, CVE-2014-0566)

- An unspecified error exists that allows the bypassing of the sandbox security restrictions. (CVE-2014-0568)

- A race condition exists in the 'MoveFileEx' call hook feature that allows attackers to bypass the sandbox protection mechanism to write files to arbitrary locations. Note that this issue only affects Adobe Acrobat 11.x. This issue has not been officially fixed in APSB14-20; however, it is unlikely to be exploitable due to a related defense-in-depth change in version 11.0.09. (CVE-2014-9150)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Adobe Acrobat 10.1.12 / 11.0.09 or later.

See Also

https://helpx.adobe.com/security/products/reader/apsb14-20.html

http://www.nessus.org/u?9107f739

Plugin Details

Severity: Critical

ID: 77711

File Name: adobe_acrobat_apsb14-20.nasl

Version: 1.13

Type: local

Agent: windows

Family: Windows

Published: 9/16/2014

Updated: 11/25/2019

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.0

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2014-0568

Vulnerability Information

CPE: cpe:/a:adobe:acrobat

Required KB Items: SMB/Registry/Enumerated, installed_sw/Adobe Acrobat

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/16/2014

Vulnerability Publication Date: 9/16/2014

Reference Information

CVE: CVE-2014-0560, CVE-2014-0561, CVE-2014-0563, CVE-2014-0565, CVE-2014-0566, CVE-2014-0567, CVE-2014-0568, CVE-2014-9150

BID: 69821, 69823, 69824, 69825, 69826, 69827, 69828, 71366