Threat Advisory

Vulnerabilities in Adobe Acrobat, Microsoft Excel Could Lead to Arbitrary Code Execution

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

Several critical vulnerabilities were identified and patched in Adobe Acrobat and Microsoft Excel software. Additionally, Researchers disclosed six vulnerabilities in the Weston Embedded µC-HTTP HTTP server implementation. Exploitation of these vulnerabilities could result in arbitrary code execution, posing significant security risks.[/subscribe_to_unlock_form]

Summary:

Several critical vulnerabilities were identified and patched in Adobe Acrobat and Microsoft Excel software. Additionally, Researchers disclosed six vulnerabilities in the Weston Embedded µC-HTTP HTTP server implementation. Exploitation of these vulnerabilities could result in arbitrary code execution, posing significant security risks.[emaillocker id="1283"]

Adobe Acrobat Vulnerabilities:

Researchers has discovered two use-after-free vulnerabilities in Adobe Acrobat PDF reader, both with the potential for arbitrary code execution. The first vulnerability, tracked as CVE-2023-44336, involves the Thermometer JavaScript object in Acrobat Reader. An attacker could exploit this by using specially crafted JavaScript code to trigger a use-after-free vulnerability, leading to memory corruption and code execution. The second vulnerability, CVE-2023-44372, affects page event processing in Acrobat Reader, operating similarly to the first.

Microsoft Excel Vulnerability:

A use-after-free vulnerability, identified as CVE-2023-36041, was found in Microsoft Office Professional Plus 2019, specifically in the Excel spreadsheet creation software. This vulnerability in the ElementType attribute parsing could allow remote code execution on the targeted machine. An attacker would need to trick the user into opening a specially crafted Excel spreadsheet to exploit this vulnerability.

Weston Embedded µC-HTTP Server Vulnerabilities:

Researchers uncovered six vulnerabilities in the Weston Embedded µC-HTTP, an open-source embedded HTTP server and client module for µC/TCP-IP, an embedded operating system. Three of these vulnerabilities, CVE-2023-28391,CVE-2023-28379, and CVE-2023-31247, are memory corruption vulnerabilities that could result in arbitrary code execution. Attackers could exploit these by sending specially crafted packets. CVE-2023-25181 and CVE-2023-27882 also lead to code execution, caused by buffer overflows triggered by specially crafted packets. Additionally, CVE-2023-24585 is an out-of-bounds write vulnerability occurring during the parsing of an HTTP request method, potentially leading to heap corruption.

Recommendations:

  • We strongly recommend you update Acrobat Reader DC and Acrobat DC to version 23.006.20380,and Acrobat Reader 2020  and Acrobat 2020 to version 20.005.30539.
  • We strongly recommend you apply and update for Microsoft Excel Remote Code Execution Vulnerability.
    Download from here: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36041
  • We strongly recommend you update Weston Embedded µC-HTTP to version 3.08.00.

References:

The following reports contain further technical details:

https://blog.talosintelligence.com/vulnerabilities-in-adobe-acrobat-microsoft-excel-could-lead-to-arbitrary-code-execution/

[/emaillocker]
crossmenu