BugId OOBR[0x900]+0x18 824.345 @ acrord32.exe!acroform.api+0x48BD03 summary

BugId: OOBR[0x900]+0x18 824.345
Location: acrord32.exe!acroform.api+0x48BD03
Description: An Access Violation exception happened at 0x27A82018 while attempting to read memory at 0x27A82018; 24/0x18 bytes beyond a 2304/0x900 bytes heap block at 0x27A81700. This indicates an Out-Of-Bounds (OOB) access bug was triggered.
Version: AcroRd32.exe: 18.11.20035.2003 (x86)
AcroForm.api: 18.11.20035.2003 (x86)
Security impact: Potentially exploitable security issue that might allow information disclosure and (less likely) arbitrary code execution.
Arguments: ['/n', 'OOBR0x48BD03.pdf']

BugId version 2018-11-21 19:42 by SkyLined. Licensed to netanelbs for commercial use.

Stack

  1. AcroForm.api + 0x48BD03 (id: 824, no function symbol available)
  2. MSVCR120.dll!_heap_alloc + 0x21 (inlined function, id: 345) [[f:\dd\vctools\crt\crtw32\heap\malloc.c @ 57]]
  3. MSVCR120.dll!malloc + 0x49 [[f:\dd\vctools\crt\crtw32\heap\malloc.c @ 92]]
  4. MSVCR120.dll!operator new + 0x1D [[f:\dd\vctools\crt\crtw32\heap\new.cpp @ 59]]
⇓ click on the title of a section to open or close it.