PDF±à¼­Æ÷Able2ExtractÁ½¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-11-06

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5088£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º8.8

CVE±àºÅ£ºCVE-2019-5089£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º8.8


Ó°Ïì°æ±¾


Investintech Able2Extract Professional 14.0.7 x64


Îó²î¸ÅÊö


Investintech Able2Extract ProfessionalÊǼÓÄôóInvestintech¹«Ë¾µÄÒ»¿îPDFÎĵµ×ª»»Æ÷ºÍ±à¼­Æ÷¡£¡£¡£¸Ã²úÆ·Ö§³ÖPDFÎĵµÉ¨Ãè¡¢PDF±à¼­ºÍPDFÉó²éµÈ£¬£¬£¬£¬£¬£¬ÊÊÓÃÓÚWindows¡¢MacºÍLinuxµÈƽ̨¡£¡£¡£Æäרҵ°æÔÚ135¸ö¹ú¼Ò/µØÇøÓµÓÐÁè¼Ý25ÍòÃûÓû§¡£¡£¡£


˼¿ÆTalosÑо¿Ö°Ô±·¢Ã÷InvestintechµÄAble2Extract Professional¹¤¾ß±£´æÁ½¸öÄÚ´æËð»µÎó²î£ºCVE-2019-5088ºÍCVE-2019-5089£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽèÖúÌØÖÆµÄBMPÎļþ»òÕßJPEGÎļþʹÓÃÎó²îÔÚÓû§ÏµÍ³ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://www.investintech.com¡£¡£¡£


²Î¿¼Á´½Ó


https://blog.talosintelligence.com/2019/11/vuln-spotlight-RCE-investintech-able2extract-nov-2019.html