Latest Comments
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM

Attack code targets unpatched Adobe Reader flaw

  • Email a Friend
  • Print Page
Attack code targets unpatched Adobe Reader flaw
By Tom Sanders
Oct 17, 2007 10:13 AM
Tags: Attack | code | targets | unpatched | Adobe | Reader | flaw
An anonymous security researcher has published a proof of concept exploit for a known vulnerability in Adobe Reader, Adobe's PDF reader.

A user by the name of Cyanid-E unveiled his creation in a posting to the Full Disclosure security mailing list on Tuesday. The vulnerability has been confirmed on a fully patched Windows XP system running Adobe Acrobat Reader 8.1 and Internet Explorer 7.

The Gnucitizen blog published details about the vulnerability late September. The blog didn't post proof of concept code at the time because it expected that Adobe would be slow to respond. Proof of concept code can easily be turned into live attack code. The publication of code therefore could put users at risk.

The proof of concept demonstrates the exploit by opening the calculator application when users open a specially crafted PDF file. Although the code is harmless, criminals could easily change the code to have it install malware or recruit a system into a botnet.

Adobe acknowledged the flaw earlier this month and published a workaround that protects users.

A spokesperson for Adobe told vnunet.com that the company is aware of the proof of concept. The company preparing to release an update within the next two weeks.

Adobe recommends that users implement the workaround and use extreme caution when they viewing and downloading "unsolicited communications".

Copyright © 2008 vnunet.com

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers