Adobe Acrobat 9.1.2 NOS Local Privilege Escalation Exploit

2009-07-21 / 2009-07-22
Credit: Jeremy Brown
Risk: Medium
Local: Yes
Remote: No
CVE: N/A
CWE: N/A

Adobe Acrobat 9.1.2 NOS Local Privilege Escalation Exploit This exploit is based on the brief information provided by Nine:Situations:Group (http://securityreason.com/exploitalert/6674). Exploiting improper permissions is fun. A few notes are in order though. The getPlus service (that I tested, via 9.1.2) isn't installed as an "Automatic" service, therefore making it slightly harder (but not hard) to practically use to your advantage. But I tested running this code under a GUEST account and it worked pretty good (just the first time though). Change the values as needed, compile and run. Things could be more or less silent, lethal or non-lethal... it is completely up to you. Things cannot get much simpler than this :) Tested on Windows XP SP3 + Adobe Acrobat 9.1.2 (installed from adobe's download manager, then updated).

References:

http://securityreason.com/exploitalert/6674
(exploit)
http://securityreason.com/download/11/15
(exploit zip)


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top