Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Windows --> Category: infos

Adobe Download Manager Detection Vulnerability Scan


Vulnerability Scan Summary
Checks for Adobe Download Manager version < 2.2

Detailed Explanation for this Vulnerability Test

Synopsis :

The remote Windows host has an application that is prone to a buffer
overflow attack.

Description :

There is a version Adobe Download Manager installed on the remote
Windows host that is vulnerable to a remote buffer overflow attack
because the application fails to perform boundary checks while
processing AOM files. In order to trigger this issue, a possible hacker
needs to entice a user to visit a website hosting the malicious AOM
file or send the AOM file as an email attachment and have the user
click on it. Successful exploitation of this issue might result in
arbitrary code execution.

See also :

http://research.eeye.com/html/advisories/published/AD20061205.html
http://archives.neohapsis.com/archives/fulldisclosure/2006-12/0092.html
http://www.adobe.com/support/security/bulletins/apsb06-19.html

Solution :

Either uninstall the application or upgrade to Adobe Download Manager
version 2.2 or later.

Threat Level:

Medium / CVSS Base Score : 5.6
(AV:R/AC:H/Au:NR/C:P/I:P/A:P/B:N)

Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.