Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Advisories

February 25th, 2009, 08:24 GMT · By

Adobe Reader Critical Flaw Still Exploitable with JavaScript Disabled

SHARE:

Adjust text size:


Maliciously-crafted PDF files exploit unpatched Reader vulnerability
Enlarge picture
Experts from vulnerability research firm Secunia warn that disabling JavaScript in Adobe Reader and Acrobat products does not efficiently protect against the recently-disclosed 0-day remote code execution vulnerability affecting them. Until Adobe will address the problem, another security researcher has created an unofficial patch.

Several security vendors and independent researchers have recently warned that an unpatched vulnerability in Adobe Reader and Acrobat, which allows for arbitrary code execution and denial of service, is being actively exploited in the wild through maliciously-crafted PDF files. Adobe has acknowledged the flaw, which it has classified as critical, but has noted that a security fix will not be deployed until March.

An analysis released by the ShadowServer cyber-crime fighting outfit has concluded that disabling JavaScript in Adobe Reader and Acrobat is a temporary mitigation solution, which will prevent the code execution issue. "The malicious PDF's in the wild exploit a vulnerability in a non-JavaScript function call. However, they do use some JavaScript to implement a heap spray for successful code execution. The malicious PDF's in the wild contain JavaScript that is used to fill the heap with shellcode," Matt Richard, one of the security researchers who have performed the analysis, explains.

However, reputed vulnerability research company Secunia warns in a blog post that, while the exploits currently used in attacks are blocked by disabling JavaScript, this does not address the vulnerability itself and remote code execution is still possible. "During our analysis, Secunia managed to create a reliable, fully working exploit, which does not use JavaScript and can therefore successfully compromise users, who may think they are safe because JavaScript support has been disabled," Secunia's Chief Security Specialist Carsten Eiram announces.

Meanwhile, Lurene Grenier, analyst team lead with Sourcefire's Vulnerability Research Team (VRT) has put together what she calls a "homebrew" unsanctioned patch. "The patch is just a replacement DLL – AcroRd32.dll to be precise. […] Unzip it into C:\Program Files\Adobe\Reader 9.0\Reader\ and allow it to overwrite the old version," the researcher explains. The patch, which is 19 MB in size when unpacked, is only for Adobe Reader version 9, users of version 8 being required to upgrade before applying it.

Obviously, as Ms. Grenier points out, this patch comes with no warranty whatsoever, and while she notes that "It WILL prevent all current attacks using the method I described," there might be other newer attacks, which could bypass it. Therefore, security experts conclude that there isn't much that can be done until Adobe rolls out its own update on March 11th, except for exercising extreme caution regarding the origin of the open PDF files.

Update:
This article has been modified to reflect Laurene Grenier's correct gender.

TELL US WHAT YOU THINK:

2,221 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Adobe Reader 0-Day Critical Vulnerability Exploited in the Wild

Botnet Serving Browser-Targeted Exploits

PDF Passwords 100 Times Less Secure in Acrobat 9

Recently Patched Adobe Reader Critical Flaw Targeted by Hackers

Adobe Reader and Acrobat 8 Plagued by Remote Code Execution Vulnerabilities

READER COMMENTS:


Comment #1 by: A Reader on 26 Feb 2009, 22:44 UTC reply to this comment

Dear Ms. Constantin, ;)

Lurene is female.

Regards,

A Reader


Comment #2 by: Lucian Constantin on 27 Feb 2009, 07:52 UTC reply to this comment

Thank you for pointing out that error. Indeed she is. I have corrected the article.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM