Intrusion Prevention

Adobe.Reader.Image.Cache.Race.Condition.Remote.Code.Execution

Description

This indicates an attack attempt against a Code Execution vulnerability in Adobe Reader and Acrobat.
The vulnerability is caused by an error when the vulnerable software handles a malicious PDF file. An attacker can trick an unsuspecting user into visiting a malicious webpage and execute arbitrary code within the context of the application.

Affected Products

Adobe Reader XI (11.0.06) and earlier 11.x versions for Windows and Macintosh
Adobe Reader X (10.1.9) and earlier 10.x versions for Windows and Macintosh
Adobe Acrobat XI (11.0.06) and earlier 11.x versions for Windows and Macintosh
Adobe Acrobat X (10.1.9) and earlier 10.x versions for Windows and Macintosh

Impact

System Compromise: Remote attackers can execute arbitrary code within the context of the target users

Recommended Actions

Upgrade to the latest version available from the website.
http://helpx.adobe.com/security/products/reader/apsb14-15.html

CVE References

CVE-2014-0528