Security in Context: The BeyondTrust Blog

Welcome to the Zeroday Tracker: Your Vulnerability Watchlist

Get critical updates on the latest zeroday threats, including impact, mitigation and protection information - only from BeyondTrust.

SumatraPDF “fz_crash_abort()” Null Byte Write Remote Code Execution Vulnerability

Disclosed January 10, 2012    Fully Patched

Vulnerability Description:

A NULL write vulnerability in the fz_crash_abort() function allows an attacker to write NULL bytes to an attacker-controlled address in memory. This can corrupt memory, allowing an attacker to run arbitrary code within the context of the currently logged on user.


SumatraPDF (Krzysztof Kowalczyk)

Vulnerable Software/Devices:

  • SumatraPDF 1.x

Vulnerability Severity:


Exploit Availability:


Exploit Impact:

Remote Code Execution
Remote Code Execution Exploitation of this vulnerability is possible through the use of methods like drive-by attacks. Remote attackers who successfully exploit this vulnerability will be able to execute code on the vulnerable system with the same rights as the currently logged on user.

BeyondTrust Prevention and Detection:

BeyondTrust's Retina® Network Security Scanner scans devices to detect for this vulnerability.

  • 15780 - SumatraPDF Memory Corruption Vulnerability
  • 15781 - SumatraPDF Memory Corruption Vulnerability - x64


Update to SumatraPDF 2.0.




Leave a Reply