Wednesday, March 31, 2010

Adobe Reader 7-8 File Execution No Javascript

This is a vuln found by Didier Stevens (hxxp://blog.didierstevens.com/2010/03/29/escape-from-pdf/), since his POC isn't yet finish, this is one of my own, the pdf adds a admin user account to the system (username: x ;password: x).


Tested in Adobe Reader 9.3

Download POC here!

Enjoy it!

Check it out!

Adobe Reader File Execution - Add User POC from iamjuza on Vimeo.


There is more pocs in the forge stay tuned!