15 Dec 2009
Security experts are warning Adobe customers to be extra vigilant following the discovery of an attack that attempts to exploit a new zero-day vulnerability in Adobe's Reader and Acrobat products.
In a blog posting late yesterday, Symantec's Security Response team said it had received a "tip from a source" that there was a potential zero-day vulnerability in the wild affecting Reader and Acrobat.
"We have indeed confirmed the existence of a 0-day vulnerability in these products," the posting continued.
"The PDF file we discovered arrives as an email attachment. The attack attempts to lure email recipients into opening the attachment. When the file is opened, a malicious file is dropped and run on a fully patched system with either Adobe Reader or Acrobat installed. Symantec products detect the file as Trojan.Pidief.H."
Adobe has since confirmed it has received and is investigating the "reports of a vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions".
"We will provide an update as soon as we have more information," read a post on the firm's Product Security Incident Response Team (PSIRT) blog.
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
Orange and Intel talk us through the ins and outs of their San Diego smartphone
Connect with V3.co.uk
The wrong printers, for the wrong tasks on the wrong contracts
Who leads the BI pack and who should we be watching out for?
2nd & 3rd Line CRM Support Analyst / MS CRM Systsems...
Digital Insight Manager, Hertfordshire, £28,000. An...
Enterprise / Solutions Architect. Salary £60,000 - £90...
Business Intelligence Developer - Leeds. Salary £35,000...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?