Adobe Reader XI privilege escalation


...i know, not privilege escalation in classical way...

 

hi.

 

with both current versions of adobe reader x , xi, standard users able repair adobe reader going via appwiz.cpl/control panel.

 

problem is: if reader opened, windows needs restart finish repairing...problem is, if standard users not allowed restart computer (think of terminal servers dozens of clients logged on), may restart server, causing real trouble. gpos in place deny standard users privilege shutdown/restart computer, buggy adobe reader makes possible.

side note: while uac prompt users supply admin credentials when trying uninstall adobe reader, not prompt when trying repair. that's bug.

 

tested on win8/server 2012, server 2008 r2. adobe reader 11.0.3/10.1.7

http://www.adobe.com/devnet/reader.html

 

you may want check dev people shut down , how disable it, being user-to-user forum, , not frequented development personnel. i'm sure there's simple code change disable it, however, without restart, repair becomes useless reader cannot repoen until proper reg keys , dll files amended per repair, know that.

 

there may code change enable uac repairs. understanding uninstall may remove shared files, , that's parameter windows prompt uac. repair changes installed files using existing files, windows doesn't see potential damage.



More discussions in Acrobat Reader


adobe

Comments

Popular posts from this blog

how to devide a circle into equal parts

"Could not fill because there are not enough opaque source pixels" - not solved by any other thread

Why can't I change the billing info for my account?