Adobe eBook Reader 2.2 File Restoration Privilege Escalation Vulnerability

Ruben Garrote Garca 19.07.2002 Verified
Local Exploits Windows

Exploit Code

source: http://www.securityfocus.com/bid/5273/info

Adobe eBook Reader is a client side application which is able to view Adobe eBooks, available for Microsoft Windows and Macintosh OS 9. eBooks are electronic books which provide some protection for content. Users may be able to view a book, but have limited publisher defined privileges to copy content.

It is possible to bypass some quota restrictions. Non-zero quotas on copying and printing content may be bypassed by repeatedly restoring certain files used to maintain state from backups.

This vulnerability has been reported in versions of eBook Reader for Microsoft Windows. It may, however, exist on other platforms.

Data\Vouchers\*.*
Data\GB.dbd
Data\Category.etb
Data\Library*.etb
Data\Library*.vld