Adobe Acrobat Reader DC
CVE-2022-34226 - Out-Of-Bounds Read
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
ASUS Aura Sync
CVE-2019-17603 - Local Privilege Escalation (LPE)
The kernel driver
ene.sys shipped with ASUS Aura Sync version 1.07.71
contains a vulnerability in the code that handles IOCTL requests.
Exploitation of this vulnerability can result in:
- local denial of service attacks (system crash due to a kernel panic), or
- local execution of arbitrary code at the kernel level (complete system compromise)
The issue can be triggered by sending a specially crafted IOCTL request. For a successful attack no special user rights are required to exploit the vulnerability.
HiDrive Desktop Client
CVE-2019-9486 - Local Privilege Escalation (LPE)
This vulnerability allows a low-privileged user to escalate privileges to SYSTEM-level. The vulnerability is due to the insecure implementation of inter-process communications (IPC), which allows a low-privilege user to inject and execute code by hijacking the insecure communications with a vulnerable .NET service. The affected .NET service is running with SYSTEM-level privileges. As a result, the injected code is run at the SYSTEM-level, bypassing privilege restrictions and allowing the user to gain full control of the system.
- CVE-2019-15746 - Command Injection
- CVE-2019-15747 - Privilege Escalation
- CVE-2019-15748 - Authorisation Bypass
- CVE-2019-15749 - Account Takeover
- CVE-2019-15750 - Cross-Site-Scripting (XSS)
- CVE-2019-15751 - Unrestricted File Upload
- CVE-2018-12939 - Directory Traversal
- CVE-2018-12940 - Unrestricted File Upload
- CVE-2018-12941 - Remote Code Execution
- CVE-2018-12942 - SQL Injection
- CVE-2018-12943 - Cross-Site Scripting (XSS)
- CVE-2018-12944 - Persistent Cross-Site Scripting (XSS)