NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Advisories

Advisories


Adobe Reader Users Targeted Again via Unpatched Vulnerability

Disable JavaScript until next Tuesday

By Lucian Constantin, Web News Editor

9th of October 2009, 08:25 GMT

Adjust text size:


In-the-wild malformed PDF exploit zero-day Adobe Reader vulnerability
Enlarge picture
Attackers are exploiting a zero-day vulnerability in the latest versions of Adobe's Reader and Acrobat products to compromise computers. The company recommends disabling JavaScript as a temporary solution until a patch is shipped on October 13.

The vulnerability, identified as CVE-2009-3459, can be used to remotely execute arbitrary code on a computer running the latest Windows flavor of Adobe Reader or Acrobat (9.1.3). In order to exploit it, attackers have to trick users into opening maliciously crafted PDF files.

Adobe credits Chia-Ching Fang and the Taiwanese Information and Communication Security Technology Service Center with the discovery of this flaw, which it says is currently being exploited in the wild as part of limited targeted attacks. The company plans to address the flaw in its upcoming quarterly security update set to ship on October 13.

However, if past experience is any indication, attacks are likely to escalate during the upcoming days as more cybercriminal gangs get their hands on the exploit. Until a patch is delivered, Adobe recommends disabling JavaScript support in the products, as it renders the current exploitation technique ineffective.

This can be achieved by unchecking the "Enable Acrobat JavaScript" checkbox from Adobe Reader's Preferences menu, although David Lenoe from Adobe's Product Security Incident Response Team (PSIRT) points out that this might not ensure 100% protection. "A variant that does not rely on JavaScript could be possible," he warns.

It is notable that users running Windows Vista with Data Execution Prevention (DEP) enabled are safe from arbitrary code execution. However, since unsuccessful exploitation will result in a denial of service condition, their product might crash.

Another method of protection is to ensure that your AV product is up to date, as Adobe is working with antivirus vendors to identify the malicious PDF files. "In the meantime, Adobe is also in contact with Antivirus and Security vendors regarding the issue and recommends users [to] keep their anti-virus definitions up to date," Mr. Lenoe notes.

TAGS:

Adobe Reader | critical vulnerability | CVE-2009-3459 | 0-day exploit | malicious PDF
Read by 1,344 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (5.0/5) 2 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2010 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Over 62,000 New URLs Serving Exploit Cocktail

Adobe's Failure to Update Vulnerable Software

Adobe Fixes XSS Vulnerabilities in ColdFusion and JRun

Flash Vulnerability Exploited Through Excel Spreadsheets

Adobe Reader and Acrobat Critical Updates Available

Adobe Criticized for Shipping Insecure Reader Version

Adobe Plugs Thirteen Holes in Reader and Acrobat on Patch Tuesday

Adobe to Improve Its Incident Response Process

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM