Slashdot Mirror


Security Researcher Drops 15 Vulnerabilities for Windows and Adobe Reader

mask.of.sanity writes: Google Project Zero hacker Mateusz Jurczyk has dropped 15 remote code execution vulnerabilities, including a single devastating hack against Adobe Reader and Windows he reckons beats all exploit defenses. He said, "The extremely powerful primitive provided by the vulnerability, together with the fact that it affected all supported versions of both Adobe Reader and Microsoft Windows (32-bit) – thus making it possible to create an exploit chain leading to a full system compromise with just a single bug – makes it one of the most interesting security issues I have discovered so far." Jurczyk published a video demonstration of the exploit for 32-bit and 64-bit systems. His slides are here [PDF].

3 of 117 comments (clear)

  1. PDF link to PDF exploit by Carewolf · · Score: 5, Funny

    Sorry, I am not clicking on a PDF link that demonstrates a PDF attack.

  2. Drops? by thechemic · · Score: 5, Insightful

    He dropped them from his to do list?

    He was carrying them around and dropped them?

    Slang for "He published them" ?

    He dropped them from his research list?

    He dropped the vulnerabilities from his own systems?

    Apparently "Slashdot" means to "Slash" the English language with slang. Can we please "DROP" the amateur reporting styles?

    --
    Let's make like a bird... and get the flock outta here.
    1. Re:Drops? by belthize · · Score: 5, Funny

      He held the exploits palm down before dropping them and then simply walked away exclaiming "Mateusz out".