PDF±à¼­Æ÷Able2ExtractÁ½¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-11-06

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5088£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬ £¬CVSS·ÖÖµ£º8.8

CVE±àºÅ£ºCVE-2019-5089£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬ £¬CVSS·ÖÖµ£º8.8


Ó°Ïì°æ±¾


Investintech Able2Extract Professional 14.0.7 x64


Îó²î¸ÅÊö


Investintech Able2Extract ProfessionalÊǼÓÄôóInvestintech¹«Ë¾µÄÒ»¿îPDFÎĵµ×ª»»Æ÷ºÍ±à¼­Æ÷¡£¡£¡£¡£¡£¡£¸Ã²úÆ·Ö§³ÖPDFÎĵµÉ¨Ãè¡¢PDF±à¼­ºÍPDFÉó²éµÈ£¬£¬ £¬ÊÊÓÃÓÚWindows¡¢MacºÍLinuxµÈƽ̨¡£¡£¡£¡£¡£¡£Æäרҵ°æÔÚ135¸ö¹ú¼Ò/µØÇøÓµÓÐÁè¼Ý25ÍòÃûÓû§¡£¡£¡£¡£¡£¡£


˼¿ÆTalosÑо¿Ö°Ô±·¢Ã÷InvestintechµÄAble2Extract Professional¹¤¾ß±£´æÁ½¸öÄÚ´æËð»µÎó²î£ºCVE-2019-5088ºÍCVE-2019-5089£¬£¬ £¬¹¥»÷Õ߿ɽèÖúÌØÖÆµÄBMPÎļþ»òÕßJPEGÎļþʹÓÃÎó²îÔÚÓû§ÏµÍ³ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬ £¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://www.investintech.com¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://blog.talosintelligence.com/2019/11/vuln-spotlight-RCE-investintech-able2extract-nov-2019.html