First published: Mon Sep 15 2008(Updated: )
A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Explorer 7, allows remote attackers to cause a denial of service (browser crash) via an src property value with an invalid acroie:// URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | =9 | |
Internet Explorer | =7 | |
Microsoft Windows Vista |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4071 has been classified as a denial of service vulnerability, causing crashes in the browser.
To mitigate CVE-2008-4071, update Adobe Acrobat to the latest version that addresses this vulnerability.
CVE-2008-4071 affects Adobe Acrobat 9 when used with Internet Explorer 7 on Windows Vista.
Yes, CVE-2008-4071 can be exploited remotely by sending a malicious acroie:// URL causing a browser crash.
The primary symptom of CVE-2008-4071 exploitation is the unexpected crash of the browser while handling the ActiveX control.