First published: Tue Feb 12 2008(Updated: )
Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via a crafted PDF file that calls an insecure JavaScript method in the EScript.api plug-in. NOTE: this issue might be subsumed by CVE-2008-0655.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | <=8.1.1 | |
Adobe Acrobat Reader Notification Manager | <=8.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5663 is considered to be of high severity due to its ability to allow remote code execution through malicious PDF files.
To fix CVE-2007-5663, update to Adobe Reader and Acrobat version 8.1.2 or later, which includes security patches.
CVE-2007-5663 affects Adobe Reader and Acrobat versions 8.1.1 and earlier.
Yes, CVE-2007-5663 can be exploited remotely if a user opens a crafted PDF file containing malicious JavaScript.
Yes, CVE-2007-5663 may be related to CVE-2008-0655, which addresses similar issues.