PT-2020-2844 · Microsoft · Windows Pdf Library+2

Published

2020-05-12

·

Updated

2021-07-21

·

CVE-2020-1096

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Edge PDF Reader (affected versions not specified) Microsoft Windows PDF Library (affected versions not specified)
Description A remote code execution issue exists due to improper handling of objects in memory by the Microsoft Edge PDF Reader and the Microsoft Windows PDF Library. This could allow an attacker to execute arbitrary code in the context of the current user by exploiting the vulnerability with a specially crafted Microsoft PDF file. If the current user has administrative rights, an attacker could gain control of the affected system, enabling them to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations For Microsoft Edge PDF Reader, update to a version that properly handles objects in memory to prevent remote code execution. For Microsoft Windows PDF Library, apply the necessary patches or updates to fix the DirectWrite Use-After-Free issue and prevent remote code execution. As a temporary workaround, consider restricting the use of the Microsoft Edge PDF Reader and the Microsoft Windows PDF Library until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02998
CVE-2020-1096
ZDI-20-641

Affected Products

Edge
Edge Pdf Reader
Windows Pdf Library