CVE-2007-5020: Code Injection
Unspecified vulnerability in Adobe Acrobat and Reader 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted PDF file, related to the mailto: option and Internet Explorer 7 on Windows XP. NOTE: this information is based upon a vague pre-advisory by a reliable researcher.
Affected Software
Event History
Frequently Asked Questions
Which environments are specifically identified as exposed?
The reported issue specifically involves Adobe Acrobat and Reader 8.1 on Windows, in connection with Internet Explorer 7 on Windows XP. The available information does not establish impact for other versions or operating systems.
What does exploitation require?
An attacker would need to provide a crafted PDF file and have it processed in the affected environment. The issue is described as remotely exploitable without authentication and can result in arbitrary code execution.
How certain are the technical details of this report?
The description states that the information was based on a vague pre-advisory from a reliable researcher. As a result, the available data does not provide enough detail to determine affected default settings, indicators of compromise, or a specific workaround if patching is unavailable.