Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2010-2883 PoC — Adobe Reader和Acrobat CoolType.dll栈缓冲区溢出漏洞

Source
Associated Vulnerability
Title:Adobe Reader和Acrobat CoolType.dll栈缓冲区溢出漏洞 (CVE-2010-2883)
Description:Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.
Description
Playing with CVE-2010-2883
Readme
# CVE-2010-2883
PoC for CVE-2010-2883 using TTD research, Metasploit techniques, BOF+ROP and HEAP spraying for educational purposes only.
File Snapshot

[4.0K] /data/pocs/72735298ed807b9a3c4a69a430590af6b1a83221 ├── [4.0K] binaries │   ├── [341K] AcroRd32.exe │   ├── [2.3M] CoolType.dll │   ├── [ 40M] CoolType.dll.idb │   ├── [546K] EMET.dll │   ├── [7.8M] EMET.dll.idb │   ├── [664K] icucnv36.dll │   └── [7.5M] icucnv36.dll.idb ├── [539K] CVE-2010-2883.pdf ├── [4.0K] EMET internet resources │   ├── [1.3M] bypassing-emet-4-1.pdf │   ├── [576K] emet_4_1_uncovered.pdf │   ├── [7.0M] EMET_slides.pdf │   ├── [1.8M] EMET User's Guide.pdf │   └── [5.1M] Recon2013-Elias Bachaalany-Inside EMET 4.pdf ├── [4.0K] exploit files │   ├── [ 20K] adobe_cooltype_sing_EMETBypass_calc.rb │   ├── [1.5K] msf_calc_EMETBypass_payload.asm │   ├── [ 46K] msf_calc_EMETBypass.pdf │   ├── [ 45K] msf_calc.pdf │   └── [ 66K] PDF_Password_SING.7z ├── [4.0K] Installers │   ├── [ 41M] AdbeRdr934_en_US.exe │   └── [8.3M] EMET Setup.msi └── [ 138] README.md 5 directories, 21 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →