Metasploit mailing list archives

CVE-2013-0640 is a MUST HAVE! Adobe Sandbox Bypass.


From: Richard Miles <richard.k.miles () googlemail com>
Date: Tue, 5 Mar 2013 09:29:20 -0600

Hi Metasploit Team, Egypt, HD Moore, Jduck, MC and Felipe Andres Manzano,

I'm writing to ask you to consider include an exploit for CVE-2013-0640, in
my opinion it's a great exploit and probably the most wanted of this month,
for a long time Adobe Acrobat Reader X and XI is considered safe and no
public exploit exist to bypass it. However, with MiniDuke code being
release on the web helps to learn the same technique and create and
effective and reliable exploit for Adobe Acrobat Reader X and XI.

Please, see details here:

http://msmvps.com/blogs/harrywaldron/archive/2013/02/28/adobe-pdf-security-first-exploit-to-compromise-sandbox-security-controls.aspx
http://www.securelist.com/en/blog/208194129/The_MiniDuke_Mystery_PDF_0_day_Government_Spy_Assembler_0x29A_Micro_Backdoor

I beg you, please, consider adding this exploit in metasploit.

Thank you.
_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework

Current thread: