Blog | G5 Cyber Security

Escape From PDF

This is a special PDF hack: I managed to make a PoC PDF to execute an embedded executable without exploiting any vulnerability. With Adobe Reader, the user gets a warning asking for approval to launch the action, but I can (partially) control the message displayed by the dialog. Foxit Reader displays no warning at all, the action gets executed without user interaction. Disabling JavaScript will not prevent this, and patching Adobe Reader isnt possible (Im not exploiting a vulnerability)”]

Source: https://blog.didierstevens.com/2010/03/29/escape-from-pdf/

Exit mobile version