
CVE-2021-21086의 Python 기반 익스플로잇으로, Adobe Acrobat Reader DC에서 조작된 글꼴 charstrings를 통해 셸코드를 실행하는 악성 PDF를 생성합니다.
이 익스플로잇은 Windows 10에서 Adobe Acrobat Reader DC 2020.013.20074 및 이전 버전의 렌더링 프로세스 컨텍스트에서 셸코드를 실행할 수 있게 합니다. 참고: 이 예제에서 사용된 셸코드는 계산기를 띄웁니다. 작동하려면 Adobe Reader의 샌드박스를 비활성화해야 하거나 다른 셸코드로 교체할 수 있습니다. (샌드박스가 비활성화된 상태에서) 작동하는 모습은 여기에서 확인할 수 있습니다.
작동 방식에 대한 자세한 내용은 블로그 포스트를 읽어보세요.
python3 .\generate_exploit_charstring.py --output charstring.python3 .\charstring2pdf.py --filename .\charstring --out exploit.pdf.