BugId: | OOBR[0x18]+0{-0x78~0x58#002d} caa.9e4 |
Location: | acrord32.exe!acrord32.dll+0x601BC7 |
Description: | An Access Violation exception happened at 0x39331000 while attempting to read memory at 0x39331000; at the end of a 24/0x18 bytes heap block at 0x39330FE8. This indicates an Out-Of-Bounds (OOB) access bug was triggered. An earlier out-of-bounds write was detected at 0x39330F70, 120/0x78 bytes before that block because it modified the page heap prefix pattern. |
Version: | AcroRd32.exe: 18.11.20040.19174 (x86) AcroRd32.dll: 18.11.20040.19174 (x86) |
Security impact: | Potentially exploitable security issue that might allow information disclosure and (less likely) arbitrary code execution. |
Arguments: | ['/n', 'OOBR@0x601BC7.pdf'] |
eax = 0x39330FE8 | xmm0 = 0x0 |
ebx = 0x2E35CFE0 | xmm1 = 0x0 |
ecx = 0x0 | xmm2 = 0x0 |
edx = 0x18 | xmm3 = 0x0 |
esi = 0x1 | xmm4 = 0x0 |
edi = 0x18 | xmm5 = 0x0 |
esp = 0xAFC1C4 | xmm6 = 0x0 |
ebp = 0xAFC1D0 | xmm7 = 0x0 |
39330f70 | *ba*bb*cd*ab | ║╗═½ | abcdbbba | // *0=Corrupted (should be 00), *1=Corrupted (should be 00), *2=Corrupted (should be 00), *3=Corrupted (should be 00) |
39330f74 | 00*10*d3 00 | ␀►╙␀ | 00d31000 → ffeeddcc | // *1=Corrupted (should be 00), *2=Corrupted (should be 00) |
39330f78 | *70 00 00 00 | p␀␀␀ | 00000070 | // *0=Corrupted (should be 00) |
39330f7c | 00*10 00 00 | ␀►␀␀ | 00001000 | // *1=Corrupted (should be 00) |
39330f80 | 00 00 00 00 | ␀␀␀␀ | 00000000 | |
39330f84 | 00 00 00 00 | ␀␀␀␀ | 00000000 | |
39330f88 | *84*82*b6*04 | äé╢♦ | 04b68284 → 049c463c | // *0=Corrupted (should be 00), *1=Corrupted (should be 00), *2=Corrupted (should be 00), *3=Corrupted (should be 00) |
39330f8c | *ba*bb*ba*dc | ║╗║▄ | dcbabbba | // *0=Corrupted (should be 00), *1=Corrupted (should be 00), *2=Corrupted (should be 00), *3=Corrupted (should be 00) |
39330f90 | *fc*7f*9a*5e | ⁿ⌂Ü^ | 5e9a7ffc → ffec8b55 | // *0=Corrupted (should be 00), *1=Corrupted (should be 00), *2=Corrupted (should be 00), *3=Corrupted (should be 00) |
39330f94 | 00 00 00 00 | ␀␀␀␀ | 00000000 | |
39330f98 | 00 00 00 00 | ␀␀␀␀ | 00000000 | |
39330f9c | 00 00 00 00 | ␀␀␀␀ | 00000000 | |
39330fa0 | *ba*bb*cd*ab | ║╗═½ | abcdbbba | // *0=Corrupted (should be 00), *1=Corrupted (should be 00), *2=Corrupted (should be 00), *3=Corrupted (should be 00) |
39330fa4 | 00*10*d3 00 | ␀►╙␀ | 00d31000 → ffeeddcc | // *1=Corrupted (should be 00), *2=Corrupted (should be 00) |
39330fa8 | *3e 00 00 00 | >␀␀␀ | 0000003e | // *0=Corrupted (should be 00) |
39330fac | 00*10 00 00 | ␀►␀␀ | 00001000 | // *1=Corrupted (should be 00) |
39330fb0 | 00 00 00 00 | ␀␀␀␀ | 00000000 | |
39330fb4 | 00 00 00 00 | ␀␀␀␀ | 00000000 | |
39330fb8 | *14*de*95*04 | ¶▐ò♦ | 0495de14 → 049bfbb4 | // *0=Corrupted (should be 00), *1=Corrupted (should be 00), *2=Corrupted (should be 00), *3=Corrupted (should be 00) |
39330fbc | *ba*bb*ba*dc | ║╗║▄ | dcbabbba | // *0=Corrupted (should be 00), *1=Corrupted (should be 00), *2=Corrupted (should be 00), *3=Corrupted (should be 00) |
39330fc0 | 00 00 00 00 | ␀␀␀␀ | 00000000 | |
39330fc4 | *09 00*09*c0 | ○␀○└ | c0090009 | // *0=Corrupted (should be 00), *2=Corrupted (should be 00), *3=Corrupted (should be 00) |
39330fc8 | *bb bb cd ab | ╗╗═½ | abcdbbbb | // *0=Page heap StartStamp |
39330fcc | *00 10 d3 00 | ␀►╙␀ | 00d31000 → ffeeddcc | // *0=Page heap Heap |
39330fd0 | *18 00 00 00 | ↑␀␀␀ | 00000018 | // *0=Page heap RequestedSize |
39330fd4 | *00 10 00 00 | ␀►␀␀ | 00001000 | // *0=Page heap ActualSize |
39330fd8 | 00 00 00 00 | ␀␀␀␀ | 00000000 | |
39330fdc | 00 00 00 00 | ␀␀␀␀ | 00000000 | |
39330fe0 | *6c e8 b0 04 | lΦ░♦ | 04b0e86c → 04b1dfec | // *0=Page heap StackTrace |
39330fe4 | *bb bb ba dc | ╗╗║▄ | dcbabbbb | // *0=Page heap EndStamp |
39330fe8 | *00 00 00 00 | ␀␀␀␀ | 00000000 | // *0=Heap block start |
39330fec | 00 00 00 00 | ␀␀␀␀ | 00000000 | |
39330ff0 | 00 00 00 00 | ␀␀␀␀ | 00000000 | |
39330ff4 | 00 00 00 00 | ␀␀␀␀ | 00000000 | |
39330ff8 | 00 00 00 00 | ␀␀␀␀ | 00000000 | |
39330ffc | 00 00 00 00 | ␀␀␀␀ | 00000000 | |
39331000 | -- inaccessible -- | // *0=Access violation, *0=Heap block end, *0=Allocation end | ||
39331004 | -- inaccessible -- | |||
39331008 | -- inaccessible -- | |||
3933100c | -- inaccessible -- | |||
39331010 | -- inaccessible -- | |||
39331014 | -- inaccessible -- | |||
39331018 | -- inaccessible -- | |||
3933101c | -- inaccessible -- | |||
39331020 | -- inaccessible -- | |||
39331024 | -- inaccessible -- | |||
39331028 | -- inaccessible -- | |||
3933102c | -- inaccessible -- | |||
39331030 | -- inaccessible -- | |||
39331034 | -- inaccessible -- | |||
39331038 | -- inaccessible -- | |||
3933103c | -- inaccessible -- | |||
39331040 | -- inaccessible -- | |||
39331044 | -- inaccessible -- | |||
39331048 | -- inaccessible -- | |||
3933104c | -- inaccessible -- | |||
39331050 | -- inaccessible -- | |||
39331054 | -- inaccessible -- | |||
39331058 | -- inaccessible -- | |||
3933105c | -- inaccessible -- | |||
39331060 | -- inaccessible -- | |||
39331064 | -- inaccessible -- | |||
39331068 | -- inaccessible -- | |||
3933106c | -- inaccessible -- | |||
39331070 | -- inaccessible -- | |||
39331074 | -- inaccessible -- | |||
39331078 | -- inaccessible -- | |||
3933107c | -- inaccessible -- | |||
39331080 | -- inaccessible -- | |||
39331084 | -- inaccessible -- | |||
39331088 | -- inaccessible -- | |||
3933108c | -- inaccessible -- | |||
39331090 | -- inaccessible -- | |||
39331094 | -- inaccessible -- | |||
39331098 | -- inaccessible -- | |||
3933109c | -- inaccessible -- | |||
393310a0 | -- inaccessible -- | |||
393310a4 | -- inaccessible -- | |||
393310a8 | -- inaccessible -- | |||
393310ac | -- inaccessible -- | |||
393310b0 | -- inaccessible -- | |||
393310b4 | -- inaccessible -- | |||
393310b8 | -- inaccessible -- | |||
393310bc | -- inaccessible -- | |||
393310c0 | -- inaccessible -- | |||
393310c4 | -- inaccessible -- | |||
393310c8 | -- inaccessible -- | |||
393310cc | -- inaccessible -- | |||
393310d0 | -- inaccessible -- | |||
393310d4 | -- inaccessible -- | |||
393310d8 | -- inaccessible -- | |||
393310dc | -- inaccessible -- | |||
393310e0 | -- inaccessible -- | |||
393310e4 | -- inaccessible -- | |||
393310e8 | -- inaccessible -- | |||
393310ec | -- inaccessible -- | |||
393310f0 | -- inaccessible -- | |||
393310f4 | -- inaccessible -- | |||
393310f8 | -- inaccessible -- | |||
393310fc | -- inaccessible -- | |||
39331100 | -- inaccessible -- | |||
39331104 | -- inaccessible -- | |||
39331108 | -- inaccessible -- | |||
3933110c | -- inaccessible -- | |||
39331110 | -- inaccessible -- | |||
39331114 | -- inaccessible -- | |||
39331118 | -- inaccessible -- | |||
3933111c | -- inaccessible -- | |||
39331120 | -- inaccessible -- | |||
39331124 | -- inaccessible -- | |||
39331128 | -- inaccessible -- | |||
3933112c | -- inaccessible -- | |||
39331130 | -- inaccessible -- | |||
39331134 | -- inaccessible -- | |||
39331138 | -- inaccessible -- | |||
3933113c | -- inaccessible -- | |||
39331140 | -- inaccessible -- | |||
39331144 | -- inaccessible -- | |||
39331148 | -- inaccessible -- | |||
3933114c | -- inaccessible -- | |||
39331150 | -- inaccessible -- | |||
39331154 | -- inaccessible -- | |||
39331158 | -- inaccessible -- | |||
3933115c | -- inaccessible -- | |||
39331160 | -- inaccessible -- | |||
39331164 | -- inaccessible -- | |||
39331168 | -- inaccessible -- | |||
3933116c | -- inaccessible -- | |||
39331170 | -- inaccessible -- | |||
39331174 | -- inaccessible -- | |||
39331178 | -- inaccessible -- | |||
3933117c | -- inaccessible -- | |||
39331180 | -- inaccessible -- | |||
39331184 | -- inaccessible -- | |||
39331188 | -- inaccessible -- | |||
3933118c | -- inaccessible -- | |||
39331190 | -- inaccessible -- | |||
39331194 | -- inaccessible -- | |||
39331198 | -- inaccessible -- | |||
3933119c | -- inaccessible -- | |||
393311a0 | -- inaccessible -- | |||
393311a4 | -- inaccessible -- | |||
393311a8 | -- inaccessible -- | |||
393311ac | -- inaccessible -- | |||
393311b0 | -- inaccessible -- | |||
393311b4 | -- inaccessible -- | |||
393311b8 | -- inaccessible -- | |||
393311bc | -- inaccessible -- | |||
393311c0 | -- inaccessible -- | |||
393311c4 | -- inaccessible -- | |||
393311c8 | -- inaccessible -- | |||
393311cc | -- inaccessible -- |
5ee01b36 | 8d4df8 | lea ecx,[ebp-8] |
5ee01b39 | 51 | push ecx |
5ee01b3a | 50 | push eax |
5ee01b3b | 6a1c | push 1Ch |
5ee01b3d | e8b985a4ff | call AcroRd32!AXWasInitViaPDFL+0x11d2 (5e84a0fb) |
5ee01b42 | 83c40c | add esp,0Ch |
5ee01b45 | 84c0 | test al,al |
5ee01b47 | 740f | je AcroRd32!CTJPEGRect::operator=+0x1b37 (5ee01b58) |
5ee01b49 | ff75f8 | push dword ptr [ebp-8] |
5ee01b4c | e8c8bba2ff | call AcroRd32!AcroWinMainSandbox+0x3795 (5e82d719) |
5ee01b51 | 8bd8 | mov ebx,eax |
5ee01b53 | 59 | pop ecx |
5ee01b54 | 85db | test ebx,ebx |
5ee01b56 | 7504 | jne AcroRd32!CTJPEGRect::operator=+0x1b3b (5ee01b5c) |
5ee01b58 | 33c0 | xor eax,eax |
5ee01b5a | eb23 | jmp AcroRd32!CTJPEGRect::operator=+0x1b5e (5ee01b7f) |
5ee01b5c | 53 | push ebx |
5ee01b5d | ff750c | push dword ptr [ebp+0Ch] |
5ee01b60 | ff75fc | push dword ptr [ebp-4] |
5ee01b63 | ff7508 | push dword ptr [ebp+8] |
5ee01b66 | 57 | push edi |
5ee01b67 | e83e010000 | call AcroRd32!CTJPEGRect::operator=+0x1c89 (5ee01caa) |
5ee01b6c | 8a45fc | mov al,byte ptr [ebp-4] |
5ee01b6f | 57 | push edi |
5ee01b70 | 891e | mov dword ptr [esi],ebx |
5ee01b72 | 884604 | mov byte ptr [esi+4],al |
5ee01b75 | e8a4e0a2ff | call AcroRd32!AcroWinMainSandbox+0x5c9a (5e82fc1e) |
5ee01b7a | 83c418 | add esp,18h |
5ee01b7d | 8bc6 | mov eax,esi |
5ee01b7f | 5f | pop edi |
5ee01b80 | 5b | pop ebx |
5ee01b81 | 5e | pop esi |
5ee01b82 | 8be5 | mov esp,ebp |
5ee01b84 | 5d | pop ebp |
5ee01b85 | c3 | ret |
5ee01b86 | 55 | push ebp |
5ee01b87 | 8bec | mov ebp,esp |
5ee01b89 | 8a4d10 | mov cl,byte ptr [ebp+10h] |
5ee01b8c | 33c0 | xor eax,eax |
5ee01b8e | 53 | push ebx |
5ee01b8f | 8b5d2c | mov ebx,dword ptr [ebp+2Ch] |
5ee01b92 | 33d2 | xor edx,edx |
5ee01b94 | 56 | push esi |
5ee01b95 | 8d7001 | lea esi,[eax+1] |
5ee01b98 | d3e6 | shl esi,cl |
5ee01b9a | 57 | push edi |
5ee01b9b | 85f6 | test esi,esi |
5ee01b9d | 7413 | je AcroRd32!CTJPEGRect::operator=+0x1b91 (5ee01bb2) |
5ee01b9f | 8bc3 | mov eax,ebx |
5ee01ba1 | 8bce | mov ecx,esi |
5ee01ba3 | 33ff | xor edi,edi |
5ee01ba5 | 668938 | mov word ptr [eax],di |
5ee01ba8 | 8d401c | lea eax,[eax+1Ch] |
5ee01bab | 668978f2 | mov word ptr [eax-0Eh],di |
5ee01baf | 49 | dec ecx |
5ee01bb0 | 75f1 | jne AcroRd32!CTJPEGRect::operator=+0x1b82 (5ee01ba3) |
5ee01bb2 | 8b7d28 | mov edi,dword ptr [ebp+28h] |
5ee01bb5 | 85ff | test edi,edi |
5ee01bb7 | 0f84aa000000 | je AcroRd32!CTJPEGRect::operator=+0x1c46 (5ee01c67) |
5ee01bbd | 8b450c | mov eax,dword ptr [ebp+0Ch] |
5ee01bc0 | eb05 | jmp AcroRd32!CTJPEGRect::operator=+0x1ba6 (5ee01bc7) |
5ee01bc2 | 3bd7 | cmp edx,edi |
5ee01bc4 | 7309 | jae AcroRd32!CTJPEGRect::operator=+0x1bae (5ee01bcf) |
5ee01bc6 | 42 | inc edx |
5ee01bc7 | 803c0200 | cmp byte ptr [edx+eax],0 // current instruction |
5ee01bcb | 74f5 | je AcroRd32!CTJPEGRect::operator=+0x1ba1 (5ee01bc2) |
5ee01bcd | 3bd7 | cmp edx,edi |
5ee01bcf | 0f8492000000 | je AcroRd32!CTJPEGRect::operator=+0x1c46 (5ee01c67) |
5ee01bd5 | 8b4508 | mov eax,dword ptr [ebp+8] |
5ee01bd8 | 8b0490 | mov eax,dword ptr [eax+edx*4] |
5ee01bdb | 3bc6 | cmp eax,esi |
5ee01bdd | 0f8da6000000 | jge AcroRd32!CTJPEGRect::operator=+0x1c68 (5ee01c89) |
5ee01be3 | 6bc01c | imul eax,eax,1Ch |
5ee01be6 | 33c9 | xor ecx,ecx |
5ee01be8 | 41 | inc ecx |
5ee01be9 | 66890c18 | mov word ptr [eax+ebx],cx |
5ee01bed | 8b4514 | mov eax,dword ptr [ebp+14h] |
5ee01bf0 | 0fb60c02 | movzx ecx,byte ptr [edx+eax] |
5ee01bf4 | 8b4508 | mov eax,dword ptr [ebp+8] |
5ee01bf7 | 6b04901c | imul eax,dword ptr [eax+edx*4],1Ch |
5ee01bfb | 894c1804 | mov dword ptr [eax+ebx+4],ecx |
5ee01bff | 8b4508 | mov eax,dword ptr [ebp+8] |
5ee01c02 | 6b0c901c | imul ecx,dword ptr [eax+edx*4],1Ch |
5ee01c06 | 8b4518 | mov eax,dword ptr [ebp+18h] |
5ee01c09 | 8b0490 | mov eax,dword ptr [eax+edx*4] |
5ee01c0c | 89441908 | mov dword ptr [ecx+ebx+8],eax |
5ee01c10 | 8b4d08 | mov ecx,dword ptr [ebp+8] |
5ee01c13 | 6b04911c | imul eax,dword ptr [ecx+edx*4],1Ch |
5ee01c17 | 89541810 | mov dword ptr [eax+ebx+10h],edx |
5ee01c1b | 6b04911c | imul eax,dword ptr [ecx+edx*4],1Ch |
5ee01c1f | 89541814 | mov dword ptr [eax+ebx+14h],edx |
5ee01c23 | 8b450c | mov eax,dword ptr [ebp+0Ch] |
5ee01c26 | 0fb60c02 | movzx ecx,byte ptr [edx+eax] |
5ee01c2a | 8b4508 | mov eax,dword ptr [ebp+8] |
5ee01c2d | 6b04901c | imul eax,dword ptr [eax+edx*4],1Ch |
5ee01c31 | 894c1818 | mov dword ptr [eax+ebx+18h],ecx |
5ee01c35 | 33c9 | xor ecx,ecx |
5ee01c37 | 8b4508 | mov eax,dword ptr [ebp+8] |
5ee01c3a | 6b04901c | imul eax,dword ptr [eax+edx*4],1Ch |
5ee01c3e | 66894c180e | mov word ptr [eax+ebx+0Eh],cx |
5ee01c43 | 8b4518 | mov eax,dword ptr [ebp+18h] |
5ee01c46 | 8b4d1c | mov ecx,dword ptr [ebp+1Ch] |
5ee01c49 | 390c90 | cmp dword ptr [eax+edx*4],ecx |
5ee01c4c | 0f9cc0 | setl al |
5ee01c4f | 0fb6c8 | movzx ecx,al |
5ee01c52 | 8b4508 | mov eax,dword ptr [ebp+8] |
5ee01c55 | 6b04901c | imul eax,dword ptr [eax+edx*4],1Ch |
5ee01c59 | 42 | inc edx |
5ee01c5a | 66894c180c | mov word ptr [eax+ebx+0Ch],cx |
5ee01c5f | 3bd7 | cmp edx,edi |
5ee01c61 | 0f8256ffffff | jb AcroRd32!CTJPEGRect::operator=+0x1b9c (5ee01bbd) |
5ee01c67 | 66837d2400 | cmp word ptr [ebp+24h],0 |
5ee01c6c | 7416 | je AcroRd32!CTJPEGRect::operator=+0x1c63 (5ee01c84) |
5ee01c6e | 8b4508 | mov eax,dword ptr [ebp+8] |
5ee01a1c | 8bec | mov ebp,esp |
5ee01a1e | 51 | push ecx |
5ee01a1f | 51 | push ecx |
5ee01a20 | 57 | push edi |
5ee01a21 | 6a10 | push 10h |
5ee01a23 | e8f1bca2ff | call AcroRd32!AcroWinMainSandbox+0x3795 (5e82d719) |
5ee01a28 | 8bf8 | mov edi,eax |
5ee01a2a | 59 | pop ecx |
5ee01a2b | 85ff | test edi,edi |
5ee01a2d | 0f84a8000000 | je AcroRd32!CTJPEGRect::operator=+0x1aba (5ee01adb) |
5ee01a33 | 53 | push ebx |
5ee01a34 | 56 | push esi |
5ee01a35 | 8b7524 | mov esi,dword ptr [ebp+24h] |
5ee01a38 | 8bc6 | mov eax,esi |
5ee01a3a | c1e002 | shl eax,2 |
5ee01a3d | 50 | push eax |
5ee01a3e | e8d6bca2ff | call AcroRd32!AcroWinMainSandbox+0x3795 (5e82d719) |
5ee01a43 | 8bd8 | mov ebx,eax |
5ee01a45 | 59 | pop ecx |
5ee01a46 | 85db | test ebx,ebx |
5ee01a48 | 7446 | je AcroRd32!CTJPEGRect::operator=+0x1a6f (5ee01a90) |
5ee01a4a | 8d45fc | lea eax,[ebp-4] |
5ee01a4d | 50 | push eax |
5ee01a4e | 56 | push esi |
5ee01a4f | 53 | push ebx |
5ee01a50 | ff7508 | push dword ptr [ebp+8] |
5ee01a53 | e84c030000 | call AcroRd32!CTJPEGRect::operator=+0x1d83 (5ee01da4) |
5ee01a58 | 83c410 | add esp,10h |
5ee01a5b | 85c0 | test eax,eax |
5ee01a5d | 7531 | jne AcroRd32!CTJPEGRect::operator=+0x1a6f (5ee01a90) |
5ee01a5f | 8a4dfc | mov cl,byte ptr [ebp-4] |
5ee01a62 | 40 | inc eax |
5ee01a63 | d3e0 | shl eax,cl |
5ee01a65 | 85c0 | test eax,eax |
5ee01a67 | 7427 | je AcroRd32!CTJPEGRect::operator=+0x1a6f (5ee01a90) |
5ee01a69 | 8365f800 | and dword ptr [ebp-8],0 |
5ee01a6d | 8d4df8 | lea ecx,[ebp-8] |
5ee01a70 | 51 | push ecx |
5ee01a71 | 50 | push eax |
5ee01a72 | 6a1c | push 1Ch |
5ee01a74 | e88286a4ff | call AcroRd32!AXWasInitViaPDFL+0x11d2 (5e84a0fb) |
5ee01a79 | 83c40c | add esp,0Ch |
5ee01a7c | 84c0 | test al,al |
5ee01a7e | 7410 | je AcroRd32!CTJPEGRect::operator=+0x1a6f (5ee01a90) |
5ee01a80 | ff75f8 | push dword ptr [ebp-8] |
5ee01a83 | e891bca2ff | call AcroRd32!AcroWinMainSandbox+0x3795 (5e82d719) |
5ee01a88 | 8945f8 | mov dword ptr [ebp-8],eax |
5ee01a8b | 59 | pop ecx |
5ee01a8c | 85c0 | test eax,eax |
5ee01a8e | 7504 | jne AcroRd32!CTJPEGRect::operator=+0x1a73 (5ee01a94) |
5ee01a90 | 33c0 | xor eax,eax |
5ee01a92 | eb45 | jmp AcroRd32!CTJPEGRect::operator=+0x1ab8 (5ee01ad9) |
5ee01a94 | 50 | push eax |
5ee01a95 | 56 | push esi |
5ee01a96 | ff751c | push dword ptr [ebp+1Ch] |
5ee01a99 | 8b7514 | mov esi,dword ptr [ebp+14h] |
5ee01a9c | ff7518 | push dword ptr [ebp+18h] |
5ee01a9f | 56 | push esi |
5ee01aa0 | ff7510 | push dword ptr [ebp+10h] |
5ee01aa3 | ff750c | push dword ptr [ebp+0Ch] |
5ee01aa6 | ff75fc | push dword ptr [ebp-4] |
5ee01aa9 | ff7508 | push dword ptr [ebp+8] |
5ee01aac | 53 | push ebx |
5ee01aad | e8d4000000 | call AcroRd32!CTJPEGRect::operator=+0x1b65 (5ee01b86) // call |
5ee01ab2 | 8b45f8 | mov eax,dword ptr [ebp-8] // return address |
5ee01ab5 | 8907 | mov dword ptr [edi],eax |
5ee01ab7 | 668b4520 | mov ax,word ptr [ebp+20h] |
5ee01abb | 6689470c | mov word ptr [edi+0Ch],ax |
5ee01abf | 33c0 | xor eax,eax |
5ee01ac1 | 6689470e | mov word ptr [edi+0Eh],ax |
5ee01ac5 | 8b45fc | mov eax,dword ptr [ebp-4] |
5ee01ac8 | 53 | push ebx |
5ee01ac9 | 884704 | mov byte ptr [edi+4],al |
5ee01acc | 897708 | mov dword ptr [edi+8],esi |
5ee01acf | e84ae1a2ff | call AcroRd32!AcroWinMainSandbox+0x5c9a (5e82fc1e) |
5ee01ad4 | 83c42c | add esp,2Ch |
5ee01ad7 | 8bc7 | mov eax,edi |
5ee01ad9 | 5e | pop esi |
5ee01ada | 5b | pop ebx |
5ee01adb | 5f | pop edi |
5ee01adc | 8be5 | mov esp,ebp |
5ee01ade | 5d | pop ebp |
5ee01adf | c3 | ret |
5ee01ae0 | 55 | push ebp |
5ee01ae1 | 8bec | mov ebp,esp |
5ee01ae3 | 51 | push ecx |
5ee01ae4 | 51 | push ecx |
5ee01ae5 | 56 | push esi |
5ee01ae6 | 6a10 | push 10h |
5ee01ae8 | c645fc00 | mov byte ptr [ebp-4],0 |
5ee01aec | e828bca2ff | call AcroRd32!AcroWinMainSandbox+0x3795 (5e82d719) |
5ee01af1 | 8bf0 | mov esi,eax |
5ee01af3 | 59 | pop ecx |
5ee01af4 | 85f6 | test esi,esi |
5ee01af6 | 0f8485000000 | je AcroRd32!CTJPEGRect::operator=+0x1b60 (5ee01b81) |
5ee01afc | 53 | push ebx |
5ee01afd | 8b5d0c | mov ebx,dword ptr [ebp+0Ch] |
5ee01b00 | 8bc3 | mov eax,ebx |
5ee01b02 | c1e002 | shl eax,2 |
5ee01b05 | 57 | push edi |
5ee01b06 | 50 | push eax |
5ee01b07 | e80dbca2ff | call AcroRd32!AcroWinMainSandbox+0x3795 (5e82d719) |
5ee01b0c | 8bf8 | mov edi,eax |
5ee01b0e | 59 | pop ecx |
5ee01b0f | 85ff | test edi,edi |
5ee01b11 | 7445 | je AcroRd32!CTJPEGRect::operator=+0x1b37 (5ee01b58) |
5ee01b13 | 8d45fc | lea eax,[ebp-4] |
5ee01b16 | 50 | push eax |
5ee01b17 | 53 | push ebx |
5ee01b18 | 57 | push edi |
5ee01b19 | ff7508 | push dword ptr [ebp+8] |
5ee01b1c | e883020000 | call AcroRd32!CTJPEGRect::operator=+0x1d83 (5ee01da4) |
5ee01b21 | 83c410 | add esp,10h |
5ee01b24 | 85c0 | test eax,eax |
Loaded symbol image file | c:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe |
Image path | AcroRd32.exe |
Image name | AcroRd32.exe |
Timestamp | Fri May 11 00:19:40 2018 (5AF4C57C) |
CheckSum | 0022F148 |
ImageSize | 00230000 |
File version | 18.11.20040.19174 |
Product version | 18.11.20040.19174 |
File flags | 0 (Mask 3F) |
File OS | 50004 CE Win32 |
File type | 1.0 App |
File date | 00000000.00000000 |
Translations | 0409.04e4 |
CompanyName | Adobe Systems Incorporated |
ProductName | Adobe Acrobat Reader DC |
OriginalFilename | AcroRd32.exe |
ProductVersion | 18.11.20040.281318 |
FileVersion | 18.11.20040.281318 |
FileDescription | Adobe Acrobat Reader DC |
LegalCopyright | Copyright 1984-2017 Adobe Systems Incorporated and its licensors. All rights reserved. |
Loaded symbol image file | c:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.dll |
Image path | c:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.dll |
Image name | AcroRd32.dll |
Timestamp | Fri May 11 00:19:00 2018 (5AF4C554) |
CheckSum | 016EAE0A |
ImageSize | 01722000 |
File version | 18.11.20040.19174 |
Product version | 18.11.20040.19174 |
File flags | 0 (Mask 3F) |
File OS | 50004 CE Win32 |
File type | 2.0 Dll |
File date | 00000000.00000000 |
Translations | 0409.04e4 |