Cisco Talos recently discovered multiple vulnerabilities in the Nitro Pro PDF reader that could allow an attacker to execute code in the context of the application.
Nitro Pro PDF is part of Nitro Software’s Productivity Suite. Pro PDF allows users to create and modify PDFs and other digital documents. It includes support for several capabilities via third-party libraries to parse the PDFs.
- CVE-2021-21796 is a use-after-free vulnerability that can be triggered if a target opens a specially crafted, malicious PDF.
- CVE-2021-21797 is a double-free vulnerability that can cause a reference to a timeout object to be stored in two different places, eventually leading to the ability to execute code under the context of the application.
The following SNORT rules will detect exploitation attempts against this vulnerability: 57303, 57304, 57294 and 57295. Additional rules may be released in the future and current rules are subject to change, pending additional vulnerability information.
Source : Cisco Talos