HTTP: Adobe Acrobat Reader CVE-2013-5065 Malicious Dropper

This signature detects the pdf dropper that is being used in-the-wild to exploit a known privilege escalation vulnerability against Windows XP and Windows Server 2003. Successful exploitation could lead to arbitrary code execution in Kernel mode.

Extended Description

NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.

Affected Products

Microsoft windows_2003_server

Short Name
HTTP:STC:ADOBE:2013-5065-PDF
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Acrobat Adobe CVE-2013-5065 Dropper Malicious Reader
Release Date
12/04/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3727
False Positive
Unknown
Vendors

Microsoft

CVSS Score

7.2

Found a potential security threat?