CVE-2021-28588
published 2021-06-28CVE-2021-28588: Adobe RoboHelp Server version 2019.0.9 (and earlier) is affected by a Path Traversal vulnerability when parsing a crafted HTTP POST request. An authenticated…
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
6.21%
92.7th percentile
Adobe RoboHelp Server version 2019.0.9 (and earlier) is affected by a Path Traversal vulnerability when parsing a crafted HTTP POST request. An authenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | robohelp_server | <= 2019.0.9 | — |
| adobe | robohelp_server | unspecified – 2019.0.9 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Use-after-free vulnerability in Foxit PDF Reader
blogs_talos·2021-05-06·CVSS 5.5
CVE-2020-28588 [MEDIUM] Vulnerability Spotlight: Use-after-free vulnerability in Foxit PDF Reader
Aleksandar Nikolic of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered a use-after-free vulnerability in the Foxit PDF Reader.
Foxit PDF Reader is one of the most popular PDF document readers currently available. As a complete and feature-rich PDF reader, it supports JavaScript for interactive documents and dynamic forms.
TALOS-2021-1287 (CVE-2020-28588) is a use-after-free vulnerability that exists in the PDF Reader that could lead to an adversary gaining the ability to execute arbitrary code on the victim machine. An attacker needs to trick a user into opening a specially crafted, malicious PDF to exploit this vulnerability. The vulnerability specifically exists in the way Foxit PDF Reader handles certain annotation types.
Cisco Talos wo
Talos
Vulnerability Spotlight: Use-after-free vulnerability in Foxit PDF Reader
blogs_talos·2021-05-06·CVSS 5.5
CVE-2020-28588 [MEDIUM] Vulnerability Spotlight: Use-after-free vulnerability in Foxit PDF Reader
## Vulnerability Spotlight: Use-after-free vulnerability in Foxit PDF Reader
Aleksandar Nikolic of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered a use-after-free vulnerability in the Foxit PDF Reader.
Foxit PDF Reader is one of the most popular PDF document readers currently available. As a complete and feature-rich PDF reader, it supports JavaScript for interactive documents and dynamic forms.
TALOS-2021-1287 (CVE-2020-28588) is a use-after-free vulnerability that exists in the PDF Reader that could lead to an adversary gaining the ability to execute arbitrary code on the victim machine. An attacker needs to trick a user into opening a specially crafted, malicious PDF to exploit this vulnerability. The vulnerability specifically exists
2021-06-28
Published