Adobe Acrobat and Reader Collab 'getIcon()' JavaScript Method Remote Code Execution Vulnerability

A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.

Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

UPDATE (April 6, 2009): Symantec has detected active exploit attempts of this issue in the wild.

An exploit is available in the references section of this document.

The following example exploit is available:


 

Privacy Statement
Copyright 2010, SecurityFocus