CVE-2008-4071: Input Validation
A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Explorer 7, allows remote attackers to cause a denial of service (browser crash) via an src property value with an invalid acroie:// URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4071?
CVE-2008-4071 has been classified as a denial of service vulnerability, causing crashes in the browser.
How do I fix CVE-2008-4071?
To mitigate CVE-2008-4071, update Adobe Acrobat to the latest version that addresses this vulnerability.
Which software is affected by CVE-2008-4071?
CVE-2008-4071 affects Adobe Acrobat 9 when used with Internet Explorer 7 on Windows Vista.
Can CVE-2008-4071 be exploited remotely?
Yes, CVE-2008-4071 can be exploited remotely by sending a malicious acroie:// URL causing a browser crash.
What are the symptoms of CVE-2008-4071 exploitation?
The primary symptom of CVE-2008-4071 exploitation is the unexpected crash of the browser while handling the ActiveX control.