A memory corruption flaw exists in Adobe Reader and Acrobat . The program fails to sanitize user-supplied input when handling U3D data, resulting in memory corruption. With a specially crafted PDF file, a context-dependent attacker can execute arbitrary code.
Classification
Location:
Local / Remote,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Workaround,
Upgrade
Exploit:
Exploit Public,
Exploit Private,
Exploit Commercial,
Virus / Malware
Disclosure:
Vendor Verified,
Discovered in the Wild
Solution
Upgrade to version 9.4.6 or higher, as it has been reported to fix this vulnerability. It is also possible to temporarily work around the flaw by implementing the following workaround: Run in protected mode for Adobe Reader / Acrobat X.