Title: Adobe Graphics Server / Document Server Remote Command Execution Vulnerability
Severity: CRITICAL
Description:
Adobe Graphics Server is used to automate the creation of graphics for print and web. Adobe Document Server is used to automatically generate PDF documents.
Adobe Graphics Server and Document Server are prone to a vulnerability that may allow remote attackers to:
- access arbitrary graphics or PDF files
- place arbitrary graphics or PDF files on a server
- gain unauthorized access to a computer
- potentially execute arbitrary code.
An attacker can place graphics or PDF files in arbitrary locations on a computer using the 'saveContent' and 'saveOptimized' Adobe Document Server commands through the AlterCast web service that runs on TCP port 8019. The files can be placed on a computer using arbitrary file extensions. This can allow an attacker to corrupt data, because existing files may be overwritten. The 'loadContent' command can be used to obtain arbitrary graphics or PDF files from the server. This may lead to information disclosure.
An attacker can exploit this vulnerability to execute arbitrary code on a vulnerable computer and gain unauthorized access by placing a graphics or PDF file containing embedded malicious code such as JavaScript as metadata on the server and subsequently executing it. This may be accomplished by placing the file in a startup folder on the server. The file will be executed upon the next interactive login by a user. Code execution would take place with the privileges of the user.
The code execution is triggered when a user interactively logs into the Adobe Server service account. Adobe Server is installed as SYSTEM, which can allow this vulnerability to be triggered when anyone logs into the server interactively. The server may also be configured to run with lower privileges.
Adobe Graphics Server 2.0, 2.1 and Adobe Document Server 5.0, 6.0 running on Windows are affected.
Affected Products:
- Adobe Document Server 5.0
- Adobe Document Server 6.0
- Adobe Graphics Server 2.0
- Adobe Graphics Server 2.1
References:
- Adobe: Adobe Homepage
- Adobe: Security Advisory: Adobe Graphics Server and Adobe Document Server configuration
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.