This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. > Find out more here
by James Dohnert
20 Feb 2013
Adobe has confirmed that it is working to patch the zero-day exploit found in its Reader and Acrobat software.
Earlier, security researches had warned of an exploit in the programs which could lead to hackers taking control of affected systems. Adobe reported that a fix for the issue should come sometime during the week of 18 February.
Adobe says that it is working on a patch for the programs on Windows, Mac, and Linux platforms, correcting flaws in Acrobat and Reader software versions nine to 9.5.3.
Until the issue is corrected Adobe recommended that administrators enable Protect View within the program's registry. Protect View is a feature that prevents documents from performing any actions that could put users at risk.
"Enterprise administrators can protect Windows users across their organisation by enabling Protected View in the registry and propagating that setting via GPO or any other method," Adobe said in a statement on the exploit.
The workaround will only work with Windows systems. Protect View currently isn't available on Mac and Linux versions of the software.
To be put at risk of attack users would have to open a PDF carrying the malware using the programs in question. Once opened the hack may not cause any noticeable suspicious activity.
According to Sophos head of technology in Asia Pacific, Paul Ducklin, the exploit works by using a decoy document technique to spread malware.
"The exploit doesn't just take over Reader and use it to inject malware onto your PC, but also reloads Reader with a clean PDF that looks safe and behaves innocently, largely because it is innocent," wrote Ducklin in a blog post.
For Adobe, the news comes following the release of a patch which corrected a similar issue in the Flash platform. Earlier this month, Flash suffered at the hands of a similar zero-day exploit.
Latest stories from Privacy
Related videos
Related articles
Related jobs
Poll
How concerned are you by the rising tide of cyber threats?
BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10
Updating your subscription status
Connect with V3.co.uk
It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model
BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs
SQL Oracle DBA (10g, 11g, RAC, T-SQL, My SQL) - City...
C# MVC Developer/Architect (C#,ASP.NET,MVC4,SQL) Brookwood...
Application Development and Support for Propriety Trading...
Automation Tester (SQL, Frameworks, Finance - Commodity...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree