NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Advisories

Advisories


Adobe Reader Critical Flaw Still Exploitable with JavaScript Disabled

An unofficial patch has been released by a security researcher

By Lucian Constantin, Web News Editor

25th of February 2009, 08:24 GMT

Adjust text size:


Maliciously-crafted PDF files exploit unpatched Reader vulnerability
Enlarge picture
Experts from vulnerability research firm Secunia warn that disabling JavaScript in Adobe Reader and Acrobat products does not efficiently protect against the recently-disclosed 0-day remote code execution vulnerability affecting them. Until Adobe will address the problem, another security researcher has created an unofficial patch.

Several security vendors and independent researchers have recently warned that an unpatched vulnerability in Adobe Reader and Acrobat, which allows for arbitrary code execution and denial of service, is being actively exploited in the wild through maliciously-crafted PDF files. Adobe has acknowledged the flaw, which it has classified as critical, but has noted that a security fix will not be deployed until March.

An analysis released by the ShadowServer cyber-crime fighting outfit has concluded that disabling JavaScript in Adobe Reader and Acrobat is a temporary mitigation solution, which will prevent the code execution issue. "The malicious PDF's in the wild exploit a vulnerability in a non-JavaScript function call. However, they do use some JavaScript to implement a heap spray for successful code execution. The malicious PDF's in the wild contain JavaScript that is used to fill the heap with shellcode," Matt Richard, one of the security researchers who have performed the analysis, explains.

However, reputed vulnerability research company Secunia warns in a blog post that, while the exploits currently used in attacks are blocked by disabling JavaScript, this does not address the vulnerability itself and remote code execution is still possible. "During our analysis, Secunia managed to create a reliable, fully working exploit, which does not use JavaScript and can therefore successfully compromise users, who may think they are safe because JavaScript support has been disabled," Secunia's Chief Security Specialist Carsten Eiram announces.

Meanwhile, Lurene Grenier, analyst team lead with Sourcefire's Vulnerability Research Team (VRT) has put together what she calls a "homebrew" unsanctioned patch. "The patch is just a replacement DLL – AcroRd32.dll to be precise. […] Unzip it into C:\Program Files\Adobe\Reader 9.0\Reader\ and allow it to overwrite the old version," the researcher explains. The patch, which is 19 MB in size when unpacked, is only for Adobe Reader version 9, users of version 8 being required to upgrade before applying it.

Obviously, as Ms. Grenier points out, this patch comes with no warranty whatsoever, and while she notes that "It WILL prevent all current attacks using the method I described," there might be other newer attacks, which could bypass it. Therefore, security experts conclude that there isn't much that can be done until Adobe rolls out its own update on March 11th, except for exercising extreme caution regarding the origin of the open PDF files.

Update:
This article has been modified to reflect Laurene Grenier's correct gender.

TAGS:

Adobe Reader | Adobe Acrobat | vulnerability | remote code execution | 0-day exploit
Read by 1,201 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Adobe Reader 0-Day Critical Vulnerability Exploited in the Wild

Botnet Serving Browser-Targeted Exploits

PDF Passwords 100 Times Less Secure in Acrobat 9

Recently Patched Adobe Reader Critical Flaw Targeted by Hackers

Adobe Reader and Acrobat 8 Plagued by Remote Code Execution Vulnerabilities

Adobe Fixes Clickjacking and Clipboard Hijacking Vulnerabilities

Web Users at Risk of Being Spied Through Their Own Webcams and Microphones

User opinions:


Comment #1 by: A Reader on 26 Feb 2009, 22:44 GMT reply to this comment

Dear Ms. Constantin, ;)

Lurene is female.

Regards,

A Reader


Comment #2 by: Lucian Constantin on 27 Feb 2009, 07:52 GMT reply to this comment

Thank you for pointing out that error. Indeed she is. I have corrected the article.

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM