BugId: | AVR:Reserved[0x2000]@0xE50 369.313 |
Location: | acrord32.exe!verifier.dll!AVrfpDphFindBusyMemoryNoCheck |
Description: | An Access Violation exception happened at 0x29E4AE50 while read reserved but unallocated memory at 0x29E4A000-0x29E4C000. |
Version: | AcroRd32.exe: 19.10.20069.49826 (x86) verifier.dll: 10.0.17134.1 (x86) |
Security impact: | Potentially exploitable security issue, if the address can be controlled, or memory be allocated at the address rather than reserved. |
Arguments: | ['R:\\AVR@Reserved.pdf'] |
eax = 0x29E4AE50 | xmm0 = 0x0 |
ebx = 0x0 | xmm1 = 0x0 |
ecx = 0x29E4A000 | xmm2 = 0x0 |
edx = 0x29E4AE50 | xmm3 = 0x0 |
esi = 0xF5DAD40 | xmm4 = 0x0 |
edi = 0x0 | xmm5 = 0x0 |
esp = 0x6FBB34 | xmm6 = 0xC4800000 |
ebp = 0x6FBB80 | xmm7 = 0x4040000000000000 |
0f5d892d | 8b4d08 | mov ecx,dword ptr [ebp+8] |
0f5d8930 | 81c184000000 | add ecx,84h |
0f5d8936 | 51 | push ecx |
0f5d8937 | e8e4f0ffff | call verifier!InsertHeadList (0f5d7a20) |
0f5d893c | 5d | pop ebp |
0f5d893d | c20800 | ret 8 |
verifier!AVrfpDphFindBusyMemoryNoCheck: | ||
0f5d8940 | 8bff | mov edi,edi |
0f5d8942 | 55 | push ebp |
0f5d8943 | 8bec | mov ebp,esp |
0f5d8945 | 6afe | push 0FFFFFFFEh |
0f5d8947 | 6878a25f0f | push offset verifier!_alloca_probe+0x2a (0f5fa278) |
0f5d894c | 68409c5f0f | push offset verifier!_except_handler4 (0f5f9c40) |
0f5d8951 | 64a100000000 | mov eax,dword ptr fs:[00000000h] |
0f5d8957 | 50 | push eax |
0f5d8958 | 83c4d4 | add esp,0FFFFFFD4h |
0f5d895b | 53 | push ebx |
0f5d895c | 56 | push esi |
0f5d895d | 57 | push edi |
0f5d895e | a160e65f0f | mov eax,dword ptr [verifier!__security_cookie (0f5fe660)] |
0f5d8963 | 3145f8 | xor dword ptr [ebp-8],eax |
0f5d8966 | 33c5 | xor eax,ebp |
0f5d8968 | 50 | push eax |
0f5d8969 | 8d45f0 | lea eax,[ebp-10h] |
0f5d896c | 64a300000000 | mov dword ptr fs:[00000000h],eax |
0f5d8972 | 8965e8 | mov dword ptr [ebp-18h],esp |
0f5d8975 | 837d0c00 | cmp dword ptr [ebp+0Ch],0 |
0f5d8979 | 7507 | jne verifier!AVrfpDphFindBusyMemoryNoCheck+0x42 (0f5d8982) |
0f5d897b | 33c0 | xor eax,eax |
0f5d897d | e95e010000 | jmp verifier!AVrfpDphFindBusyMemoryNoCheck+0x1a0 (0f5d8ae0) |
0f5d8982 | 8b450c | mov eax,dword ptr [ebp+0Ch] |
0f5d8985 | 50 | push eax |
0f5d8986 | 8b4d08 | mov ecx,dword ptr [ebp+8] |
0f5d8989 | 51 | push ecx |
0f5d898a | e8b1f4ffff | call verifier!DphDelayFreeLookup (0f5d7e40) |
0f5d898f | 8b10 | mov edx,dword ptr [eax] |
0f5d8991 | 39550c | cmp dword ptr [ebp+0Ch],edx |
0f5d8994 | 7527 | jne verifier!AVrfpDphFindBusyMemoryNoCheck+0x7d (0f5d89bd) |
0f5d8996 | c745c400010000 | mov dword ptr [ebp-3Ch],100h |
0f5d899d | c745c800000000 | mov dword ptr [ebp-38h],0 |
0f5d89a4 | 8b450c | mov eax,dword ptr [ebp+0Ch] |
0f5d89a7 | 8945cc | mov dword ptr [ebp-34h],eax |
0f5d89aa | 8d4dc4 | lea ecx,[ebp-3Ch] |
0f5d89ad | 51 | push ecx |
0f5d89ae | 8b550c | mov edx,dword ptr [ebp+0Ch] |
0f5d89b1 | 52 | push edx |
0f5d89b2 | 6a00 | push 0 |
0f5d89b4 | 8b4508 | mov eax,dword ptr [ebp+8] |
0f5d89b7 | 50 | push eax |
0f5d89b8 | e813300000 | call verifier!AVrfpDphReportCorruptedBlock (0f5db9d0) |
0f5d89bd | 8b4d08 | mov ecx,dword ptr [ebp+8] |
0f5d89c0 | 8b91ac000000 | mov edx,dword ptr [ecx+0ACh] |
0f5d89c6 | 83e210 | and edx,10h |
0f5d89c9 | 0f85e2000000 | jne verifier!AVrfpDphFindBusyMemoryNoCheck+0x171 (0f5d8ab1) |
0f5d89cf | 8b450c | mov eax,dword ptr [ebp+0Ch] |
0f5d89d2 | 83e820 | sub eax,20h |
0f5d89d5 | 8945dc | mov dword ptr [ebp-24h],eax |
0f5d89d8 | 8b4d0c | mov ecx,dword ptr [ebp+0Ch] |
0f5d89db | 83e928 | sub ecx,28h |
0f5d89de | 81e100f0ffff | and ecx,0FFFFF000h |
0f5d89e4 | 894de0 | mov dword ptr [ebp-20h],ecx |
0f5d89e7 | c745fc00000000 | mov dword ptr [ebp-4],0 |
0f5d89ee | c745c400000000 | mov dword ptr [ebp-3Ch],0 |
0f5d89f5 | 8b55dc | mov edx,dword ptr [ebp-24h] |
0f5d89f8 | 813abbbbcdab | cmp dword ptr [edx],0ABCDBBBBh // current instruction |
0f5d89fe | 7530 | jne verifier!AVrfpDphFindBusyMemoryNoCheck+0xf0 (0f5d8a30) |
0f5d8a00 | 8b45dc | mov eax,dword ptr [ebp-24h] |
0f5d8a03 | 81781cbbbbbadc | cmp dword ptr [eax+1Ch],0DCBABBBBh |
0f5d8a0a | 7524 | jne verifier!AVrfpDphFindBusyMemoryNoCheck+0xf0 (0f5d8a30) |
0f5d8a0c | 8b4de0 | mov ecx,dword ptr [ebp-20h] |
0f5d8a0f | 8139eeeeeeee | cmp dword ptr [ecx],0EEEEEEEEh |
0f5d8a15 | 7519 | jne verifier!AVrfpDphFindBusyMemoryNoCheck+0xf0 (0f5d8a30) |
0f5d8a17 | 8b55e0 | mov edx,dword ptr [ebp-20h] |
0f5d8a1a | 8b4204 | mov eax,dword ptr [edx+4] |
0f5d8a1d | 8b4810 | mov ecx,dword ptr [eax+10h] |
0f5d8a20 | 3b4d0c | cmp ecx,dword ptr [ebp+0Ch] |
0f5d8a23 | 750b | jne verifier!AVrfpDphFindBusyMemoryNoCheck+0xf0 (0f5d8a30) |
0f5d8a25 | 8b55e0 | mov edx,dword ptr [ebp-20h] |
0f5d8a28 | 8b4204 | mov eax,dword ptr [edx+4] |
0f5d8a2b | 8945e4 | mov dword ptr [ebp-1Ch],eax |
0f5d8a2e | eb07 | jmp verifier!AVrfpDphFindBusyMemoryNoCheck+0xf7 (0f5d8a37) |
0f5d8a30 | c745e400000000 | mov dword ptr [ebp-1Ch],0 |
0f5d8a37 | c745fcfeffffff | mov dword ptr [ebp-4],0FFFFFFFEh |
0f5d8a3e | eb6f | jmp verifier!AVrfpDphFindBusyMemoryNoCheck+0x16f (0f5d8aaf) |
0f5d8a40 | 8b4dec | mov ecx,dword ptr [ebp-14h] |
0f5d8a43 | 8b11 | mov edx,dword ptr [ecx] |
0f5d8a45 | 8b02 | mov eax,dword ptr [edx] |
0f5d8a47 | 8945d0 | mov dword ptr [ebp-30h],eax |
0f5d8a4a | 817dd0050000c0 | cmp dword ptr [ebp-30h],0C0000005h |
0f5d8a51 | 7540 | jne verifier!AVrfpDphFindBusyMemoryNoCheck+0x153 (0f5d8a93) |
0f5d8a53 | c745c8050000c0 | mov dword ptr [ebp-38h],0C0000005h |
0f5d8a5a | 8b4dc4 | mov ecx,dword ptr [ebp-3Ch] |
0f5d8a5d | 83c920 | or ecx,20h |
0f5d8a60 | 894dc4 | mov dword ptr [ebp-3Ch],ecx |
0f5d8a63 | 8b55ec | mov edx,dword ptr [ebp-14h] |
0f5d8a66 | 8b02 | mov eax,dword ptr [edx] |
0f5d8a68 | b904000000 | mov ecx,4 |
0f5d8a6d | c1e100 | shl ecx,0 |
0f5d8a70 | 8b540814 | mov edx,dword ptr [eax+ecx+14h] |
0f5d8a74 | 8955cc | mov dword ptr [ebp-34h],edx |
0f5d8a77 | 8d45c4 | lea eax,[ebp-3Ch] |
0f5d8a7a | 50 | push eax |
0f5d8a7b | 8b4d0c | mov ecx,dword ptr [ebp+0Ch] |
0f5d8a7e | 51 | push ecx |
0f5d8a7f | 6a00 | push 0 |
0f5d8a81 | 8b5508 | mov edx,dword ptr [ebp+8] |
0f5d8a84 | 52 | push edx |
0f5d8a85 | e8462f0000 | call verifier!AVrfpDphReportCorruptedBlock (0f5db9d0) |
0f5d8a8a | c745d800000000 | mov dword ptr [ebp-28h],0 |
0f5d8a91 | eb07 | jmp verifier!AVrfpDphFindBusyMemoryNoCheck+0x15a (0f5d8a9a) |
0f5d8a93 | c745d800000000 | mov dword ptr [ebp-28h],0 |
0f5d8a9a | 8b45d8 | mov eax,dword ptr [ebp-28h] |
0f5d8a9d | c3 | ret |
0f5d8a9e | 8b65e8 | mov esp,dword ptr [ebp-18h] |
0f5d8a74 | 8955cc | mov dword ptr [ebp-34h],edx |
0f5d8a77 | 8d45c4 | lea eax,[ebp-3Ch] |
0f5d8a7a | 50 | push eax |
0f5d8a7b | 8b4d0c | mov ecx,dword ptr [ebp+0Ch] |
0f5d8a7e | 51 | push ecx |
0f5d8a7f | 6a00 | push 0 |
0f5d8a81 | 8b5508 | mov edx,dword ptr [ebp+8] |
0f5d8a84 | 52 | push edx |
0f5d8a85 | e8462f0000 | call verifier!AVrfpDphReportCorruptedBlock (0f5db9d0) |
0f5d8a8a | c745d800000000 | mov dword ptr [ebp-28h],0 |
0f5d8a91 | eb07 | jmp verifier!AVrfpDphFindBusyMemoryNoCheck+0x15a (0f5d8a9a) |
0f5d8a93 | c745d800000000 | mov dword ptr [ebp-28h],0 |
0f5d8a9a | 8b45d8 | mov eax,dword ptr [ebp-28h] |
0f5d8a9d | c3 | ret |
0f5d8a9e | 8b65e8 | mov esp,dword ptr [ebp-18h] |
0f5d8aa1 | c745e400000000 | mov dword ptr [ebp-1Ch],0 |
0f5d8aa8 | c745fcfeffffff | mov dword ptr [ebp-4],0FFFFFFFEh |
0f5d8aaf | eb2c | jmp verifier!AVrfpDphFindBusyMemoryNoCheck+0x19d (0f5d8add) |
0f5d8ab1 | 8d450c | lea eax,[ebp+0Ch] |
0f5d8ab4 | 50 | push eax |
0f5d8ab5 | 8b4d08 | mov ecx,dword ptr [ebp+8] |
0f5d8ab8 | 83c120 | add ecx,20h |
0f5d8abb | 51 | push ecx |
0f5d8abc | ff156ce0600f | call dword ptr [verifier!_imp__RtlLookupElementGenericTableAvl (0f60e06c)] |
0f5d8ac2 | 8945d4 | mov dword ptr [ebp-2Ch],eax |
0f5d8ac5 | 837dd400 | cmp dword ptr [ebp-2Ch],0 |
0f5d8ac9 | 740b | je verifier!AVrfpDphFindBusyMemoryNoCheck+0x196 (0f5d8ad6) |
0f5d8acb | 8b55d4 | mov edx,dword ptr [ebp-2Ch] |
0f5d8ace | 83ea10 | sub edx,10h |
0f5d8ad1 | 8955e4 | mov dword ptr [ebp-1Ch],edx |
0f5d8ad4 | eb07 | jmp verifier!AVrfpDphFindBusyMemoryNoCheck+0x19d (0f5d8add) |
0f5d8ad6 | c745e400000000 | mov dword ptr [ebp-1Ch],0 |
0f5d8add | 8b45e4 | mov eax,dword ptr [ebp-1Ch] |
0f5d8ae0 | 8b4df0 | mov ecx,dword ptr [ebp-10h] |
0f5d8ae3 | 64890d00000000 | mov dword ptr fs:[0],ecx |
0f5d8aea | 59 | pop ecx |
0f5d8aeb | 5f | pop edi |
0f5d8aec | 5e | pop esi |
0f5d8aed | 5b | pop ebx |
0f5d8aee | 8be5 | mov esp,ebp |
0f5d8af0 | 5d | pop ebp |
0f5d8af1 | c20800 | ret 8 |
0f5d8af4 | cc | int 3 |
0f5d8af5 | cc | int 3 |
0f5d8af6 | cc | int 3 |
0f5d8af7 | cc | int 3 |
0f5d8af8 | cc | int 3 |
0f5d8af9 | cc | int 3 |
0f5d8afa | cc | int 3 |
0f5d8afb | cc | int 3 |
0f5d8afc | cc | int 3 |
0f5d8afd | cc | int 3 |
0f5d8afe | cc | int 3 |
0f5d8aff | cc | int 3 |
verifier!AVrfpDphFindBusyMemory: | ||
0f5d8b00 | 8bff | mov edi,edi |
0f5d8b02 | 55 | push ebp |
0f5d8b03 | 8bec | mov ebp,esp |
0f5d8b05 | 83ec14 | sub esp,14h |
0f5d8b08 | 8b450c | mov eax,dword ptr [ebp+0Ch] |
0f5d8b0b | 50 | push eax |
0f5d8b0c | 8b4d08 | mov ecx,dword ptr [ebp+8] |
0f5d8b0f | 51 | push ecx |
0f5d8b10 | e82bfeffff | call verifier!AVrfpDphFindBusyMemoryNoCheck (0f5d8940) // call |
0f5d8b15 | 8945fc | mov dword ptr [ebp-4],eax // return address |
0f5d8b18 | 837dfc00 | cmp dword ptr [ebp-4],0 |
0f5d8b1c | 0f84b8000000 | je verifier!AVrfpDphFindBusyMemory+0xda (0f5d8bda) |
0f5d8b22 | 8b55fc | mov edx,dword ptr [ebp-4] |
0f5d8b25 | 8b421c | mov eax,dword ptr [edx+1Ch] |
0f5d8b28 | c1e805 | shr eax,5 |
0f5d8b2b | 83e001 | and eax,1 |
0f5d8b2e | 7527 | jne verifier!AVrfpDphFindBusyMemory+0x57 (0f5d8b57) |
0f5d8b30 | c745ec00010000 | mov dword ptr [ebp-14h],100h |
0f5d8b37 | c745f000000000 | mov dword ptr [ebp-10h],0 |
0f5d8b3e | 8b4d0c | mov ecx,dword ptr [ebp+0Ch] |
0f5d8b41 | 894df4 | mov dword ptr [ebp-0Ch],ecx |
0f5d8b44 | 8d55ec | lea edx,[ebp-14h] |
0f5d8b47 | 52 | push edx |
0f5d8b48 | 8b450c | mov eax,dword ptr [ebp+0Ch] |
0f5d8b4b | 50 | push eax |
0f5d8b4c | 6a00 | push 0 |
0f5d8b4e | 8b4d08 | mov ecx,dword ptr [ebp+8] |
0f5d8b51 | 51 | push ecx |
0f5d8b52 | e8792e0000 | call verifier!AVrfpDphReportCorruptedBlock (0f5db9d0) |
0f5d8b57 | 8b55fc | mov edx,dword ptr [ebp-4] |
0f5d8b5a | 52 | push edx |
0f5d8b5b | 8b4508 | mov eax,dword ptr [ebp+8] |
0f5d8b5e | 50 | push eax |
0f5d8b5f | e82cfcffff | call verifier!AVrfpDphGetBlockInformation (0f5d8790) |
0f5d8b64 | 8945f8 | mov dword ptr [ebp-8],eax |
0f5d8b67 | c745f000000000 | mov dword ptr [ebp-10h],0 |
0f5d8b6e | c745ec00020000 | mov dword ptr [ebp-14h],200h |
0f5d8b75 | 8b4dfc | mov ecx,dword ptr [ebp-4] |
0f5d8b78 | 8b55f8 | mov edx,dword ptr [ebp-8] |
0f5d8b7b | 8b4120 | mov eax,dword ptr [ecx+20h] |
0f5d8b7e | 3b4208 | cmp eax,dword ptr [edx+8] |
0f5d8b81 | 741c | je verifier!AVrfpDphFindBusyMemory+0x9f (0f5d8b9f) |
0f5d8b83 | 8b4df8 | mov ecx,dword ptr [ebp-8] |
0f5d8b86 | 83c108 | add ecx,8 |
0f5d8b89 | 894df4 | mov dword ptr [ebp-0Ch],ecx |
0f5d8b8c | 8d55ec | lea edx,[ebp-14h] |
0f5d8b8f | 52 | push edx |
0f5d8b90 | 8b450c | mov eax,dword ptr [ebp+0Ch] |
0f5d8b93 | 50 | push eax |
0f5d8b94 | 6a00 | push 0 |
0f5d8b96 | 8b4d08 | mov ecx,dword ptr [ebp+8] |
0f5d8b99 | 51 | push ecx |
0f5d8b9a | e8312e0000 | call verifier!AVrfpDphReportCorruptedBlock (0f5db9d0) |
0f5d8b9f | 8b55fc | mov edx,dword ptr [ebp-4] |
0f5d8ba2 | 8b45f8 | mov eax,dword ptr [ebp-8] |
0f5d8ba5 | 8b4a30 | mov ecx,dword ptr [edx+30h] |
0f5d8ba8 | 3b4818 | cmp ecx,dword ptr [eax+18h] |
0f5d8bab | 741c | je verifier!AVrfpDphFindBusyMemory+0xc9 (0f5d8bc9) |
0f5d8bad | 8b55f8 | mov edx,dword ptr [ebp-8] |
Loaded symbol image file | C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe |
Image path | AcroRd32.exe |
Image name | AcroRd32.exe |
Timestamp | Wed Dec 19 19:58:38 2018 (5C1A86CE) |
CheckSum | 00274EFE |
ImageSize | 0026C000 |
File version | 19.10.20069.49826 |
Product version | 19.10.20069.49826 |
File flags | 0 (Mask 3F) |
File OS | 50004 CE Win32 |
File type | 1.0 App |
File date | 00000000.00000000 |
Translations | 0409.04e4 |
CompanyName | Adobe Systems Incorporated |
ProductName | Adobe Acrobat Reader DC |
OriginalFilename | AcroRd32.exe |
ProductVersion | 19.10.20069.311970 |
FileVersion | 19.10.20069.311970 |
FileDescription | Adobe Acrobat Reader DC |
LegalCopyright | Copyright 1984-2018 Adobe Systems Incorporated and its licensors. All rights reserved. |
Loaded symbol image file | C:\Windows\SysWOW64\verifier.dll |
Image path | C:\Windows\SysWOW64\verifier.dll |
Image name | verifier.dll |
Timestamp | 43EAF28C (This is a reproducible build file hash, not a timestamp) |
CheckSum | 00059CB6 |
ImageSize | 00064000 |
File version | 10.0.17134.1 |
Product version | 10.0.17134.1 |
File flags | 0 (Mask 3F) |
File OS | 40004 NT Win32 |
File type | 2.0 Dll |
File date | 00000000.00000000 |
Translations | 0409.04b0 |
CompanyName | Microsoft Corporation |
ProductName | Microsoft« Windows« Operating System |
InternalName | verifier.dll |
OriginalFilename | verifier.dll |
ProductVersion | 10.0.17134.1 |
FileVersion | 10.0.17134.1 (WinBuild.160101.0800) |
FileDescription | Standard application verifier provider dll |
LegalCopyright | ⌐ Microsoft Corporation. All rights reserved. |