Monday, April 14, 2025
HomeMalwareNew Double Zero-day Exploit Discovered in same PDF file that Affected Adobe...

New Double Zero-day Exploit Discovered in same PDF file that Affected Adobe Acrobat & Windows 7

Published on

SIEM as a Service

Follow Us on Google News

A researcher discovered new double Zero-day exploit that affected Adobe Acrobat, Reader and older Windows 7 platforms, Windows Server 2008.

This critical Zero-Day exploit discovered during the analysis conducted by Microsoft against the malicious PDF file that discovered by ESET researcher.

The malicious PDF initially reported to Microsoft as a potential exploit for an unknown Windows kernel vulnerability but the detailed research leads to find another 2 new zero-day exploit within the same PDF.

- Advertisement - Google News

Initially, this malicious PDF discovered from virustotal which is uploaded by someone. At that time it wasn’t fully prepared to attack and the exploit was in an earlier stage of the development.

Among these 2 critical zero-day exploits, first exploit attacks the Adobe JavaScript engine and run the shellcode and the second exploit affected the older version of Windows 7.

 Zero-Day Exploitation Process

Adobe Acrobat and Reader based Exploit distributed via malicious PDF as a  JPEG 2000 stream that contains the Javascript exploit code.

Later malicious JPEG 2000 stream triggers an out-of-bounds access operation and the access operation is called upon out-of-bounds memory laid out by the heap spray.

After that  corrupted vftable transfers execution into ROP chains then it transfers it into main shellcode.

Later main EoP module loads through reflective DLL loading and finally it launch the  Win32k EoP exploit.

After the successful exploitation, it will drop the .vbs file that designed to download additional payloads to compromise the Victims.

Main Win32k EoP Zero-day Exploit

A loaded PE module exploits the main Win32k elevation-of-privilege (EoP) that was taking advantages of previously unknown vulnerability that affected the windows 7 machine and not present on Windows 10 and newer products.

This exploits using the NULL page to pass malicious records and copies arbitrary data to an arbitrary kernel location.

Intially exploit calls the DLL NtAllocateVirtualMemory  to allocate a fake data structure at the NULL page.

According to Microsoft, the Exploit is working in following ways.

  1. It passes a malformed MEINFOEX structure to the SetImeInfoEx Win32k kernel function.
  2. SetImeInfoEx picks up the fake data structure allocated at the NULL page.
  3. The exploit uses the fake data structure to copy malicious instructions to +0x1a0 on the Global Descriptor Table (GDT).
  4. It calls an FWORD instruction to call into the fake GDT entry instructions.
  5. The exploit successfully calls instructions in the fake GDT entry.
  6. The instructions run shellcode allocated in user mode from kernel mode memory space.

Finally, the exploit modifies the  EPROCESS.Token of the shellcode process and bypass the System and gain the access.

You can also read the ESET Research regarding this Double Zero day Exploits.

Indicators of compromise

SHA-256: dd4e4492fecb2f3fe2553e2bcedd44d17ba9bfbd6b8182369f615ae0bd520933
SHA-1: 297aef049b8c6255f4461affdcfc70e2177a71a9+

Also Read:

Zerodium Pays Upto $1,500,000 Per Fully Functional Zeroday Exploit Submissions

Adobe Issues Patch for Critical Flash Player Zero-day Vulnerability : Its Time to Update

Zero-Day Remote Code Execution Vulnerability Discovered in Microsoft Windows JScript

Hackers Launching Massive Cyber Attack Against 800,000 DrayTek Routers by Exploiting zero-day Vulnerability

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

BPFDoor Malware Uses Reverse Shell to Expand Control Over Compromised Networks

A new wave of cyber espionage attacks has brought BPFDoor malware into the spotlight...

EU’s GDPR Article 7 Poses New Challenges for Businesses To Secure AI-Generated Image Data

As businesses worldwide embrace digital transformation, the European Union’s General Data Protection Regulation (GDPR),...

Morocco Investigation Major Data Breach Allegedly Claimed by Algerian Hackers

The National Social Security Fund (CNSS) of Morocco has confirmed that initial checks on...

Smishing Campaign Hits Toll Road Users with $5 Payment Scam

Cybersecurity researchers at Cisco Talos have uncovered a large-scale smishing campaign targeting toll road...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

BPFDoor Malware Uses Reverse Shell to Expand Control Over Compromised Networks

A new wave of cyber espionage attacks has brought BPFDoor malware into the spotlight...

Slow Pisces Group Targets Developers Using Coding Challenges Laced with Python Malware

A North Korean state-sponsored threat group known as "Slow Pisces" has been orchestrating sophisticated...

Alleged FUD Malware ‘GYware’ Advertised on Hacker Forum for $35/Month

A new Remote Access Trojan (RAT) known as "GYware" is being marketed on a...