Critical Vulnerability Information Vulnerability Overview EDB-ID: 42418 CVE: 2017-7442 Vulnerability Name: Nitro Pro PDF Reader 11.0.3.173 - Javascript API Code Execution (Metasploit) Affected Platform: Windows Vulnerability Date: 2017-08-02 Affected Application: Nitro Pro PDF Reader 11.0.3.173 Vulnerability Details Type: LOCAL Verification Status: EDB Verified Description: - This vulnerability exploits an insecure implementation of the JavaScript API in Nitro Pro PDF Reader 11.0.3.173. - The JavaScript API function allows arbitrary file writing to the filesystem. - The function enables attackers to execute local files and bypass security dialog boxes. Vulnerability Authors and Contributors Author: METASPLOIT Related Contributors: - Mr_me - Brendan Coles - ginn3r Reference Links CVE: 2017-7442 Public Advisory: Blogs Default Options and Targets Default Options: - DisablePayloadHandler => false Platform: win Default Target: 0 Related Code Snippet Vulnerability Verification and Testing Exploit test results are displayed at the bottom of the page, showing a successful shell acquisition.