Adobe Acrobat < 10.1.12 / 11.0.09 Multiple Vulnerabilities (APSB14-20)
High Nessus Plugin ID 77711
SynopsisThe version of Adobe Acrobat on the remote Windows host is affected by multiple vulnerabilities.
DescriptionThe version of Adobe Acrobat installed on the remote host is a version prior to 10.1.12 / 11.0.09. It is, therefore, affected by the following vulnerabilities :
- A use-after-free error exists that allows arbitrary code execution. (CVE-2014-0560)
- A heap-based buffer overflow exists that allows arbitrary code execution. (CVE-2014-0561, CVE-2014-0567)
- A memory corruption error exists that allows denial of service attacks. (CVE-2014-0563)
- Memory corruption errors exist that allows arbitrary code execution. (CVE-2014-0565, CVE-2014-0566)
- An unspecified error exists that allows the bypassing of the sandbox security restrictions. (CVE-2014-0568)
- A race condition exists in the 'MoveFileEx' call hook feature that allows attackers to bypass the sandbox protection mechanism to write files to arbitrary locations. Note that this issue only affects Adobe Acrobat 11.x. This issue has not been officially fixed in APSB14-20; however, it is unlikely to be exploitable due to a related defense-in-depth change in version 11.0.09. (CVE-2014-9150)
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
SolutionUpgrade to Adobe Acrobat 10.1.12 / 11.0.09 or later.