Netskope Threat Labs

FILE-PDF Acrobat Reader TIFF malformed IFD tag heap overflow attempt

IPS-SWG

1 SID: 42910

First seen
February 2022
Last seen
October 2026

Detects a PDF exploiting CVE-2017-3042, a heap overflow in Adobe Acrobat Reader's embedded TIFF parsing that can allow code execution. The rule matches the malformed image file directory tags that public exploits use to overflow the image parser.