All the latest UK technology news, reviews and analysis

Attack code targets unpatched Adobe Reader flaw

by Tom Sanders in California

17 Oct 2007

Comment: 1

  • Tweet this
Adobe Acrobat
Details about the Adobe Reader vulnerability were published in late September

A security researcher has published a proof-of-concept exploit for a known vulnerability in Adobe Reader.

The researcher, known only as 'Cyanid-E', unveiled his creation in a posting to the Full Disclosure security mailing list on Tuesday.

The vulnerability has been confirmed on a fully patched Windows XP system running Adobe's Acrobat Reader 8.1 and Internet Explorer 7.

Details about the vulnerability were published in late September on the GNU Citizen blog.

The blog did not post proof-of-concept code at the time because it expected Adobe to be slow to respond. Proof-of-concept code can easily be turned into live attack code, and the publication could have put users at risk.

The proof-of-concept demonstrates the exploit by opening the calculator application when users open a specially crafted PDF file.

Although the code is harmless, criminals could easily modify it to install malware or recruit a system into a botnet.

Adobe acknowledged the flaw earlier this month and published a workaround that protects users.

A spokesperson for Adobe told vnunet.com that the company is aware of the proof-of-concept and is preparing to release an update within the next two weeks.

Adobe recommends users to implement the workaround and use extreme caution when viewing and downloading "unsolicited communications".

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Field/Site Engineering Manager/Leader

Field/Site Engineering Manager/Leader Brief: Polar...

Product Manager, Open Repository (ref:BMC/PMR)

Product Manager, Open Repository (ref:BMC/PMR) End...

Java/JEE Software Developer-Dotcom/eCommerce Software House

Java/J2EE Software Developer/Programmer - Dotcom/ eCommerce...

Field/Site Engineering Manager/Leader

Field/Site Engineering Manager/Leader Brief: Polar...

To send to more than one email address, simply separate each address with a comma.