Microsoft Windows PDF API Jpeg2000... CVE-2016-3319 CNNVD-201608-208

9.3 AV AC AU C I A
发布: 2016-08-09
修订: 2018-10-12

### Description An exploitable out of bounds write vulnerability exists in the PDF parsing API in the latest versions of Microsoft Windows. A specially crafted PDF file can cause an out of bounds write resulting in arbitrary code execution. Vulnerability can be triggered via malicious web page or a saved PDF file delivered by other means. ### Tested Versions Microsoft Windows PDF API Windows.Data.Pdf.dll version 10.0.10.586.162 ### Product URLs http://www.microsoft.com ### CVSSv3 Score 7.5 - CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H ### Details The vulnerability is present in the Microsoft native PDF API which is available since Windows 8.1. In Windows 10, Microsoft Edge is the default application for opening PDF files enabling potential vulnerabilities in native PDF API to be exploited over the Web. There exists a vulnerability in the way Microsoft PDF API parses jpeg2000 files embedded in the PDF documents. A specially crafted jpeg2000 file can trigger a out of bounds memory...

0%
暂无可用Exp或PoC
当前有7条受影响产品信息