Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2021-45067 PoC — Adobe Acrobat Reader Memory Corruption could lead to Information Disclosure

Source
Associated Vulnerability
Title:Adobe Acrobat Reader Memory Corruption could lead to Information Disclosure (CVE-2021-45067)
Description:Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Access of Memory Location After End of Buffer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Description
Adobe Reader DC Information Leak Exploit 
Readme
# CVE-2021-45067

This bug was `Out of Bounds Read` caused by treating `ANSI` string as `Unicode` which can be exploited to leak sensitive information from the sandboxed adobe reader process.

## Blog

- [Adobe Reader - XFA - ANSI - Unicode Confusion Information Leak](https://www.hacksys.io/blogs/adobe-reader-xfa-ansi-unicode-confusion-information-leak)

## Advisory

-   [CVE-2021-45067](https://hacksys.io/advisories/HI-2021-002)

## Demo

[![Adobe Reader - XFA - ANSI - Unicode Confusion Information Leak Exploit](https://img.youtube.com/vi/2QNmhwN_I4w/0.jpg)](https://www.youtube.com/watch?v=2QNmhwN_I4w)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →