Out-of-bounds write in 3D Plugin Beta - #VU16804
Published: January 4, 2019
3D Plugin Beta
Detailed vulnerability description
The vulnerability exists due to the improper handling of logic exception in IFXASSERT function when handling certain PDF file that embeds specifically crafted 3D content. A remote attacker can trick the victim into processing a specially crafted PDF file, trigger out-of-bounds write and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.