New Adobe zero-day threat discovered

 

Symantec warns of flaw.

Security experts are warning Adobe customers to be extra vigilant following the discovery of an attack that attempts to exploit a new zero-day vulnerability in Adobe's Reader and Acrobat products.

In a blog posting late yesterday, Symantec's Security Response team said it had received a "tip from a source" that there was a potential zero-day vulnerability in the wild affecting Reader and Acrobat.

"We have indeed confirmed the existence of a 0-day vulnerability in these products," the posting continued.

"The PDF file we discovered arrives as an email attachment. The attack attempts to lure email recipients into opening the attachment. When the file is opened, a malicious file is dropped and run on a fully patched system with either Adobe Reader or Acrobat installed. Symantec products detect the file as Trojan.Pidief.H."

Adobe has since confirmed it has received and is investigating the "reports of a vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions".

"We will provide an update as soon as we have more information," read a post on the firm's Product Security Incident Response Team (PSIRT) blog.

Copyright ©v3.co.uk


New Adobe zero-day threat discovered
 
 
 
 
 
Top Stories
Vito Forte: A CIO for tough times
Fortescue Metals CIO talks vendor management and innovation.
 
Telstra shifts BigPond email to Windows Live
All data to be migrated to Microsoft cloud.
 
Vodafone Australia churn nears half a million for 2011
British joint owners 'not pleased'.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Would you be concerned about your business' email data being hosted offshore?

   |   View results
Yes
  84%
 
No
  16%
TOTAL VOTES: 243

Vote