— the blog of Webguide: an inspiration and toolkit for community groups
Random header image... Refresh for more!

PDF Reader very unsafe – disable or replace urgently

Most of us open and read PDF attachments or downloads (our banks and government departments produce many documents for download this way) despite the fact that the security of the Adobe Acrobat reader has long been suspect. But now the company has confirmed that it is positively unsafe. Ryan Narain at ZDNet has the full story. Adobe confirms PDF zero-day attacks. Disable JavaScript now

Malicious hackers are exploiting a zero-day (unpatched) vulnerability in Adobe’s ever-present PDF Reader/Acrobat software to hijack data from compromised computers.

According to an advisory from Adobe, the critical vulnerability exists in Adobe Reader and Acrobat 9.2 and earlier versions. It is being exploited in the wild.

The company has activated its security response process but declined to offer any more details until an investigation is complete.

Unfortunately, the company did not provide any mitigation guidance for customers.

The folks at ShadowServer describe the situation as “very bad.”

We did not discover this vulnerability but have received multiple reports of this issue and have examined multiple different copies of malicious PDFs that exploit this issue. This is legit and is very bad.

Here’s what we know so far:

We can tell you that this exploit is in the wild and is actively being used by attackers and has been in the wild since at least December 11, 2009. However, the number of attacks are limited and most likely targeted in nature. Expect the exploit to become more wide spread in the next few weeks and unfortunately potentially become fully public within the same timeframe. We are fully aware of all the details related to the exploit but do not plan to publish them for a few reasons:

1. There currently is no patch or update available that completely protects against this exploit.
2. There is little to no detection of these malicious PDF files from most of the major Antivirus vendors.

With that said we can tell you that this vulnerability is actually in a JavaScript function within Adobe Acrobat [Reader] itself. Furthermore the vulnerable JavaScript is obfuscated inside a zlib stream making universal detection and intrusion detection signatures much more difficult.

In the interim, Adobe PDF Reader/Acrobat users are urged to immediately disable JavaScript [as follows]:

Open Acrobat and Click: Edit -> Preferences -> JavaScript and uncheck Enable Acrobat JavaScript

Or, better yet, use an alternative PDF Reader software program.

I use one called Foxit that works perfectly well, it also has a paid version called Foxit Pro that enables me to edit most PDF files except those locked with password protection. Although there's a learning curve, its very handy.

Welcome back to Groupings blog. Now that you are a regular, please feel free to comment on any story that you feel comfortable with.

4 comments

1 Investigator Pro - Detective Tool Kit. | 7Wins.eu { 02.08.10 at 08:47:24 }

[...] PDF Reader very unsafe – disable or replace urgently — Groupings [...]

2 CharlotteVp27 { 02.13.10 at 06:50:15 }

If people are stuck with academic essay creating, therefore I would offer to buy essays from some good media essay writing service in such situation.

3 Free Essay { 03.07.10 (2 weeks ago) at 08:29:43 }

I know that we have
to know about this good topic and custom term papers.
At the paper writing services it’s easy to
order pre-finished essay or custom writing about this good topic.

4 Bianca { 03.10.10 (1 week ago) at 10:14:56 }

Good thing you published this because I did almost send some sensitive documents in PDF. I ended uo sending it as JPG files instead.

Leave a Comment

Subscribe without commenting