Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Security Fixes and Improvements

June 30th, 2010, 08:17 GMT · By

Adobe Finally Fixes /Launch Bug

SHARE:

Adjust text size:


/Launch action abuse mitigated in Adobe Reader 9.3.3
Enlarge picture
Adobe has finally addressed a bug facilitating a social engineering attack that could trick users into executing malicious programs from inside PDF documents. The technique abused shortcomings in Adobe's implementation of the PDF specification's /Launch feature.

At the beginning of April, a Belgian researcher named Didier Stevens revealed that security mechanisms surrounding the /Launch action in Adobe Reader can be bypassed. His technique, dubbed "escape from PDF," could be used to instrument very credible social engineering attacks.

When encountering a /Launch event, Adobe Reader used to display a warning window notifying users that they were about to open a file that could be malicious. The dialog window had a content box, which normally should have displayed the name of file to be launched. By exploiting a bug, Stevens was able to alter the content of this file and insert any message into it, such as misleading instructions to confirm the action.

Later that month, on April 13, Adobe launched a scheduled security update for Adobe Reader and Acrobat, but failed to address this issue. That same day, antivirus vendors started issuing alerts that /Launch-based PDF attacks were spotted in the wild.

Fortunately, the bug was fixed in the Adobe Reader and Acrobat security update released yesterday, which addresses a total of seventeen critical vulnerabilities. "This update mitigates a social engineering attack that could lead to code execution (CVE-2010-1240)," the latest security bulletin reads.

The fix has been confirmed by Didier Stevens on his blog, who reports that "Not only is the dialog box fixed, but the /Launch action is also disabled by default." Attempting to open a file in this way will now display a warning reading "This file is set to be launched by this PDF file. This is currently disallowed by your system administrator." In addition, the field containing the name of the file to be executed can no longer be altered.

TELL US WHAT YOU THINK:

8,102 hits · 8 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Security Updates Available for Adobe Reader

PDF /Launch Trick Spotted in New Attack

Malicious PDFs Abusing /Launch Feature Spotted in the Wild

New PDF-Based Arbitrary Code Execution Technique Revealed

READER COMMENTS:


Comment #1 by: skdlf on 30 Jun 2010, 20:12 UTC reply to this comment

Anyone else having a bug with the updater? It always behaves as if I didn't have the latest version of Reader, and it urges me to download and install the update I just applied. It's annoying as hell.


Comment #2 by: JG on 09 Aug 2010, 19:41 UTC reply to this comment

But what if I want users to be able to open a link that I've embedded in a PDF? It will still open Internet links (although it displays a warning first), but it won't open a network file path, which makes my document rather useless...


Comment #3 by: loudmouthbass on 23 Sep 2010, 18:08 UTC reply to this comment

can someone point me in the direction to change this back. my pdf was opening an access database, but now the user receives the "currently disallowed" message

Comment #3.1 by: Lucian Constantin on 24 Sep 2010, 10:10 GMT

Hello,

Adobe keeps several blacklists for file and URL types that can be launched from inside PDF documents.

These are located in the registry under HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\9.0\FeatureLockDown

You can edit it to allow what you need.

Comment #3.2 by: fgh on 08 Nov 2010, 03:03 GMT

Hey there Lucian. Thanks for the tip. how about a little more detail though. betting 9 out of 10 people with this problem...well let's face it, probably wouldn't think to look on the internet for a solution. But probably a good 50% of the rest still wouldn't even now how to get to the Registry Editor. What would you suggest editing and editing to?


Comment #4 by: Lisa on 29 Sep 2011, 18:18 UTC reply to this comment

We created a link to a special RDC for our inhouse users and I assume because of this 'fix' (I'm getting the error that it's disallowed) the link in the pdf'd uesr guide will no longer work. According to this article and forum entries I've read, we don't get to choose. That's a problem. Most users don't have access to the registry key to make changes, and wouldn't know how. I don't and don't.

Comment #4.1 by: John on 30 Jan 2012, 16:35 GMT

If you can get into your registry via an inhouse IT guy this should fix the issue you are having. I have attempted to make it fairly easy to follow. you might have to add |.exe:2 or |.rdc:2 to the end of the key that i mentioned below

If you go into the registry (regedit) and look under hkey_LOCAL_MACHINE - Software - Policies - Adobe - Acrobat (which ever version you have) - (version Number) - FeatureLockDown and then in cDefaultLaunchAttachmentPerms you will see the registry key tBuiltInPermList. You can edit the data in that field to open which ever type of file extension you may have a link for.


For Example: I had someone who coudlent open a .txt file. So i went in and added |.txt:2 to the list (the | is the shift \). i am not sure what the 2 really means but it then gave me the are you sure you want to open the file and i clicked okay and it went through fine. I tried putting a 3 instead of a 2 but that didnt allow for it to open.


I hope this helps everyone who has been having this issue. i found many pages saying there was a registry fix for this but untill i went through myself i have yet to see them. Let me know if this works for you also


Comment #5 by: Captain_Nemo on 10 Feb 2012, 18:11 UTC reply to this comment

really defeats the purpose of being able to create an InDesign with Interactive PDF in mind if you can't implement buttons that call up reference PDF documents. I need to have the ability to have a customer select a button to load up detailed PDF files for reference from a master document.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM