NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Advisories

Advisories


No Click Required to Exploit 0-day Adobe Reader Vulnerability

Just hovering the mouse pointer over a malicious PDF file will do the trick

By Lucian Constantin, Web News Editor

6th of March 2009, 09:19 GMT

Adjust text size:


Windows Explorer mouse-over event triggers PDF exploit code execution
Enlarge picture
The yet-unpatched critical vulnerability affecting up-to-date versions of Adobe Reader and Acrobat has just become more dangerous. A security consultant has demonstrated how to exploit the bug without needing to actually open a malformed PDF file.

It's been a little over two weeks since members of the cyber-crime fighting outfit "The Shadowserver Foundation" warned about a 0-day serious vulnerability in Adobe Reader and Acrobat, which was being exploited in the wild through maliciously-crafted PDF files.

Adobe acknowledged the vulnerability in an advisory, but only scheduled a patch for March 11, a rather long period of time for a 0-day flaw that baffled security experts. Things got even more serious when researchers from vulnerability intelligence company Secunia later announced that they had developed a working proof-of-concept exploit for it that did not rely on JavaScript.

This posed significant problems, since an initially-suggested workaround for the issue involved disabling JavaScript in Adobe Reader and Acrobat, because the exploits detected in the wild required it. However, what Didier Stevens, IT security consultant at Contraste Europe, has just recently demonstrated is far more scarier than Secunia's exploit.

According to Mr. Stevens, "Sometimes, a piece of malware can execute without even opening the file. As this is the case with the /JBIG2Decode vulnerability in PDF documents." In order to demonstrate this concept, the researcher has made use of two already available exploits and a custom one that he created himself.

As he explains, this behavior is possible due to the Windows Shell Extension that Adobe Reader and Acrobat install. This is called "Column Handler Shell Extension," and is responsible with feeding Windows Explorer with additional columns of information when listing PDF files in a directory. The existence of this shell extension opens the door to three distinct attack scenarios.

The first one involves clicking on the file to select it in Windows Explorer (single click). This action will cause the extension to actually read it in order to gather the extra information to display. The second type of attack occurs if the "Thumbnail view" option is selected in Windows Explorer. In order to generate a thumbnail, the first page of the PDF document has to be read, again executing any malicious code it contains.

The third and most intriguing scenario employs the custom PDF file that Mr. Stevens has created. This file stores the malicious stream object in the metadata instead of its pages. The information stored in the file metadata is read by Windows Explorer through the shell extension in order to generate mouse-over tooltips. Therefore, by hovering the mouse pointer over a malformed PDF file, the exploit code will be automatically executed.

It remains to be seen if this latest development will compel Adobe to release an unscheduled patch before March 11. Regardless of this fact, everyone should "be very careful when you handle malicious files," the security consultant warns. "[...] Always change the extension of malware (trojan.exe becomes trojan.exe.virus) and handle them in an isolated virus lab. Outside of that lab, [...] encrypt the malware," he advises.

TAGS:

Adobe Reader | Adobe Acrobat | JBIG2Decode | vulnerability exploitation | shell extension
Read by 1,343 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Adobe Reader Critical Flaw Still Exploitable with JavaScript Disabled

Adobe Reader 0-Day Critical Vulnerability Exploited in the Wild

Botnet Serving Browser-Targeted Exploits

PDF Passwords 100 Times Less Secure in Acrobat 9

Recently Patched Adobe Reader Critical Flaw Targeted by Hackers

Adobe Reader and Acrobat 8 Plagued by Remote Code Execution Vulnerabilities

Adobe Fixes Clickjacking and Clipboard Hijacking Vulnerabilities

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM