Summary:
Several critical vulnerabilities were identified and patched in Adobe Acrobat and Microsoft Excel software. Additionally, Researchers disclosed six vulnerabilities in the Weston Embedded µC-HTTP HTTP server implementation. Exploitation of these vulnerabilities could result in arbitrary code execution, posing significant security risks.[/subscribe_to_unlock_form]
Summary:
Several critical vulnerabilities were identified and patched in Adobe Acrobat and Microsoft Excel software. Additionally, Researchers disclosed six vulnerabilities in the Weston Embedded µC-HTTP HTTP server implementation. Exploitation of these vulnerabilities could result in arbitrary code execution, posing significant security risks.[emaillocker id="1283"]
Adobe Acrobat Vulnerabilities:
Researchers has discovered two use-after-free vulnerabilities in Adobe Acrobat PDF reader, both with the potential for arbitrary code execution. The first vulnerability, tracked as CVE-2023-44336, involves the Thermometer JavaScript object in Acrobat Reader. An attacker could exploit this by using specially crafted JavaScript code to trigger a use-after-free vulnerability, leading to memory corruption and code execution. The second vulnerability, CVE-2023-44372, affects page event processing in Acrobat Reader, operating similarly to the first.
Microsoft Excel Vulnerability:
A use-after-free vulnerability, identified as CVE-2023-36041, was found in Microsoft Office Professional Plus 2019, specifically in the Excel spreadsheet creation software. This vulnerability in the ElementType attribute parsing could allow remote code execution on the targeted machine. An attacker would need to trick the user into opening a specially crafted Excel spreadsheet to exploit this vulnerability.
Weston Embedded µC-HTTP Server Vulnerabilities:
Researchers uncovered six vulnerabilities in the Weston Embedded µC-HTTP, an open-source embedded HTTP server and client module for µC/TCP-IP, an embedded operating system. Three of these vulnerabilities, CVE-2023-28391,CVE-2023-28379, and CVE-2023-31247, are memory corruption vulnerabilities that could result in arbitrary code execution. Attackers could exploit these by sending specially crafted packets. CVE-2023-25181 and CVE-2023-27882 also lead to code execution, caused by buffer overflows triggered by specially crafted packets. Additionally, CVE-2023-24585 is an out-of-bounds write vulnerability occurring during the parsing of an HTTP request method, potentially leading to heap corruption.
Recommendations:
References:
The following reports contain further technical details:
[/emaillocker]