CVE-2010-2201
Adobe Acrobat and Reader 9.x < 9.3.3 and 8.x < 8.2.3 - Remote Code Execution via Crafted Flash Content in PDF
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2201. PoCs published by Abysssec.
AI-analyzed exploit summary This exploit generates a malicious PDF file that embeds a crafted SWF file exploiting a memory corruption vulnerability in Adobe Acrobat and Reader via the 'pushstring' command. The vulnerability allows arbitrary code execution when the PDF is opened.
Description
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content involving the (1) pushstring (0x2C) operator, (2) debugfile (0xF1) operator, and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-1285 and CVE-2010-2168.
Exploits (1)
This exploit generates a malicious PDF file that embeds a crafted SWF file exploiting a memory corruption vulnerability in Adobe Acrobat and Reader via the 'pushstring' command. The vulnerability allows arbitrary code execution when the PDF is opened.