Adobe Reader Zero-Day Exploit: Protecting Your PC

By Tony Bradley, PC World |  Security Add a new comment

Reports that a zero-day vulnerability in Adobe Acrobat and Adobe Reader is being exploited in the wild have been confirmed by Adobe in a blog post. Adobe is exploring the issue to determine how to patch it, but you're on your own in the meantime.

The popular PDF document format has made the Adobe Reader software virtually ubiquitous. Few software products are installed so pervasively that they exist on nearly every system regardless of operating system. For malware developers, targeting flaws in Adobe Reader offers an exceptionally large potential for victims.

The issue reportedly impacts Adobe Reader, and Adobe Acrobat--versions 9.2 and earlier. The good news is that attacks thus far are narrowly-focused, targeted attacks rather than widespread efforts.

Ben Greenbaum, senior research manager for Symantec Security Response, explains "The e-mails Symantec has seen thus far use fairly standard social engineering to try and lure users to open up a malicious PDF file, which Symantec detects as Trojan.Pidief.H. Symantec has an antivirus detection signature for this threat."

The Trojan horse exploits a flaw in the Adobe software to allow it to install additional malware components and further compromise the vulnerable computer. The additional malware could potentially be anything, but Symantec reports that the most prevalent malware associated with this threat right now is some type of information-stealing software.

The Shadowserver Foundation, a security watchdog organization, wrote in a blog post "We can tell you that this exploit is in the wild and is actively being used by attackers and has been in the wild since at least December 11, 2009. However, the number of attacks are limited and most likely targeted in nature. Expect the exploit to become more wide spread in the next few weeks and unfortunately potentially become fully public within the same timeframe."

The actual exploit relies on JavaScript. The Shadowserver Foundation and SANS Institute both recommend that you simply disable the execution of JavaScript within the Adobe software. In your Adobe product, go to Edit--Preferences--JavaScript, and uncheck the box next to Enable Adobe JavaScript.

Whether or not you choose to disable JavaScript in Adobe products, you should always exercise some caution and common sense before opening any email attachments. Symantec's Greenbaum points out "In general, users should be very wary of any e-mails they receive from an unknown sender that they aren't expecting. They should never open any attachments from any such e-mail, either."

Greenbaum adds "Many times, these e-mails will try to pressure users into opening the attachment or use scare tactics. If a user gets an e-mail from an unknown sender that tries to pressure them into opening an attachment, it is very likely that the attachment is malware and the e-mail should be deleted immediately."

Follow these precautions and keep your eyes open for an update soon from Adobe to patch the flaws.

Tony Bradley tweets as @PCSecurityNews, and can be contacted at his Facebook page.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question