Netskope Threat Labs

FILE-IMAGE Adobe Acrobat Pro malformed TIF heap overflow attempt

IPS-SWG

1 SID: 42844

First seen
January 2022
Last seen
October 2026

Detects a document exploiting CVE-2017-3049, a heap overflow in Adobe Acrobat's TIFF parsing that can allow code execution. The rule matches the malformed image directory tags that public exploits use to overflow the image parser.