Adobe released a patch which supposedly fixed a vulnerability in their PDF parsing products last week. Security researchers found that the patch didnt truly fix the vulnerability. The patch introduces the use of a denylist of extensions which may not be executed through the Launch functionality. In theory, this idea is pretty good, but implementation leaves much to be desired. The implementation of the denylists is much too simplistic and looks for very narrow exact matches. This means that the vulnerability can be circumvented by applying extremely simple forms of obfuscation.”]
Source: https://securelist.com/its-a-bug-not-a-feature/29722/

