All the latest UK technology news, reviews and analysis

Web attacks target PDF flaw

by Shaun Nichols

More from this author

11 Feb 2008

Be the first to comment

  • Tweet this
Adobe Acrobat Reader
The attacks target a flaw in the way Acrobat handles PDF files

Security researchers are warning users to upgrade their version of Adobe's Acrobat Reader following reports of new vulnerabilities.

The attacks target a flaw in the way Acrobat handles PDF files within Internet Explorer which could allow an attacker to remotely execute code.

Adobe released a patch for the vulnerability on Wednesday. However, security firm Sans Institute reported on Friday that it had discovered malicious banner ads which exploit the flaw.

The banner ads install Trojan files which delete any competing malware on the user's system.

Sans Institute traced the ads back to a hosting service in The Netherlands, which has since been notified and has removed the malicious files.

Greg McManus, a researcher with iDefense Labs, was credited with discovering the flaw, which was disclosed to Adobe in October last year.

IDefense reported that the malicious PDF files being used in the attack are currently undetectable by most antivirus programs. The company has provided a number of vendors with samples.

Users are urged to upgrade Adobe Acrobat Reader to version 8.1.2, which patches the vulnerability and prevents the attack being launched.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Low Latency Network Engineer, Senior Network Engineer, Multicas

Low Latency Network Engineer, Senior Network Engineer...

SQL Server DBA - (North London)

SQL DBA - (North London) North London , £45k - 50k...

Business Architect – (North London)

Business Architect – (North London) £65,000 – 75,000k...

Graduate Software Engineer - Javascript OR Android

Graduate Software Engineer - Javascript OR Android...

To send to more than one email address, simply separate each address with a comma.