This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Adobe warns users over zero-day PDF attack

by Shaun Nichols

13 Feb 2013

View Comments

  • Tweet this
Adobe headquarters in San Jose

Security experts have urged users to be cautious following the discovery of a new zero-day attack on Adobe's Reader and Acrobat platforms.

Adobe said that its Product Security Incident Response Team (PSIRT) is investigating an attack which uses modified PDF files to exploit the vulnerability.

"Adobe is aware of a report of a vulnerability in Adobe Reader and Acrobat XI (11.0.1) and earlier versions being exploited in the wild," the PSIRT said.

"We are currently investigating this report and assessing the risk to our customers."

Word of the attacks comes just hours after Adobe posted a security update to address flaws in its Flash and Shockwave platforms. The company gave no word on when a possible Reader update would be released.

Adobe's Reader and Acrobat platforms have historically been favourite targets for malware writers. The PDF file attacks are second only to Java exploits as the most commonly-targeted platforms in the wild.

Ross Barrett, senior manager of engineering for security firm Rapid7, noted that the casual way in which many users handle documents makes PDF attacks particularly dangerous.

"On any given day I would view a PDF attachment that I am not explicitly expecting with a high degree of suspicion, and this is just confirmation of those concerns," Barrett explained.

"The major risk will be via compromised 'safe' websites which are serving the malware unbeknownst to their legitimate operators."

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

16%

56%

10%

9%

9%

Popular Threads

Powered by Disqus
BlackBerry Q5

BlackBerry Q5 video demo

BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

SQL Oracle DBA (10g, 11g, RAC, T-SQL, My SQL)

SQL Oracle DBA (10g, 11g, RAC, T-SQL, My SQL) - City...

C# MVC Developer/Architect (C#,ASP.NET,MVC4,SQL) remote working

C# MVC Developer/Architect (C#,ASP.NET,MVC4,SQL) Brookwood...

Application Development/Support - Assets, Java, Perl, Python

Application Development and Support for Propriety Trading...

Automation Tester (SQL, Frameworks, Finance)

Automation Tester (SQL, Frameworks, Finance - Commodity...

Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.

To send to more than one email address, simply separate each address with a comma.