BugId OOBW[0x200]+0 a49.fdd @ acrord32.exe!acroform.api+0x48BFF8 summary

BugId: OOBW[0x200]+0 a49.fdd
Location: acrord32.exe!acroform.api+0x48BFF8
Description: An Access Violation exception happened at 0x147B9000 while attempting to write memory at 0x147B9000; at the end of a 512/0x200 bytes heap block at 0x147B8E00. This indicates an Out-Of-Bounds (OOB) access bug was triggered.
Version: AcroRd32.exe: 18.11.20035.2003 (x86)
AcroForm.api: 18.11.20035.2003 (x86)
Security impact: Potentially exploitable security issue that indicates arbitrary code execution may be possible.
Arguments: ['/n', 'OOBW0x48BFF8.pdf']

BugId version 2018-11-21 19:42 by SkyLined. Licensed to netanelbs for commercial use.

Stack

  1. AcroForm.api + 0x48BFF8 (id: a49, no function symbol available)
  2. AcroForm.api + 0x48CC06 (id: fdd, no function symbol available)
  3. AcroForm.api + 0x4847ED (no function symbol available)
  4. AcroForm.api + 0xFC654 (no function symbol available)
  5. AcroForm.api + 0x4859C4 (no function symbol available)
  6. AcroForm.api + 0x6490A3 (no function symbol available)
  7. ntdll.dll!RtlpAllocateHeap + ? (the exact offset is not known)
  8. ntdll.dll!RtlpAllocateHeapInternal + 0x179
  9. ntdll.dll!RtlAllocateHeap + 0x3E
  10. MSVCR120.dll!_heap_alloc + 0x21 (inlined function) [[f:\dd\vctools\crt\crtw32\heap\malloc.c @ 57]]
  11. MSVCR120.dll!malloc + 0x49 [[f:\dd\vctools\crt\crtw32\heap\malloc.c @ 92]]
  12. AcroForm.api + 0x8CE81 (no function symbol available)
  13. AcroForm.api + 0x14FD84 (no function symbol available)
  14. AcroForm.api + 0x628D31 (no function symbol available)
⇓ click on the title of a section to open or close it.