Adobe Reader XI privilege escalation
...i know, not privilege escalation in classical way...
hi.
with both current versions of adobe reader x , xi, standard users able repair adobe reader going via appwiz.cpl/control panel.
problem is: if reader opened, windows needs restart finish repairing...problem is, if standard users not allowed restart computer (think of terminal servers dozens of clients logged on), may restart server, causing real trouble. gpos in place deny standard users privilege shutdown/restart computer, buggy adobe reader makes possible.
side note: while uac prompt users supply admin credentials when trying uninstall adobe reader, not prompt when trying repair. that's bug.
tested on win8/server 2012, server 2008 r2. adobe reader 11.0.3/10.1.7
http://www.adobe.com/devnet/reader.html
you may want check dev people shut down , how disable it, being user-to-user forum, , not frequented development personnel. i'm sure there's simple code change disable it, however, without restart, repair becomes useless reader cannot repoen until proper reg keys , dll files amended per repair, know that.
there may code change enable uac repairs. understanding uninstall may remove shared files, , that's parameter windows prompt uac. repair changes installed files using existing files, windows doesn't see potential damage.
More discussions in Acrobat Reader
adobe
Comments
Post a Comment