Hackers target unpatched Adobe flaw

 

PDF vulnerability being exploited ahead of update.

Security experts are warning that an unpatched Adobe PDF vulnerability due to be fixed in the vendor's upcoming 12 January quarterly security update is actively being exploited in the wild.

The flaw in Acrobat and Reader software, which was first discovered in mid-December, could allow a hacker to cause a system crash and potentially take control of an affected PC.

Despite reports at the time that the flaw was actively being exploited, Adobe's director of product security and privacy, Brad Arkin, explained that the firm would not be working on a fix prior to the 12 January quarterly update because it could "negatively impact the timing of the next quarterly security update".

However, hackers appear to be stepping up their activities. A posting on security vendor Trend Micro's blog today said that a new PDF sample exploiting the same unpatched vulnerability in Acrobat and Reader has been spotted in the wild.

"The sample (detected by Trend Micro as TROJ_PIDIEF.WIA) uses the heap spray technique to execute shellcode in its stream. As a result, a malicious file detected as BKDR_POISON.UC is dropped into the system," the blog noted.

"When executed, BKDR_POISON.UC opens an instance of Internet Explorer and connects to a remote site, cecon.{BLOCKED}-show.org. Once connected, a malicious user may execute any command on the affected system."

Until 12 January, Adobe is recommending customers to either disable JavaScript in Reader and Acrobat or, for those running versions 9.2 or 8.1.7, to use the JavaScript Blacklist Framework.

Copyright ©v3.co.uk


Hackers target unpatched Adobe flaw
"Adobe, Adobe....I used to so admire you as a company, but since the Macromedia takeover your software has become increasingly buggy (to the point where I am looking for alternatives) and your ..."
By funkyg
 
 
 
Comments: 1
funkyg
Jan 8, 2010 10:26 AM
Adobe, Adobe....I used to so admire you as a company, but since the Macromedia takeover your software has become increasingly buggy (to the point where I am looking for alternatives) and your security policies are atrocious. It will "negatively impact the timing of the next quarterly security update"....yeah, and a virus coming from your software won't negatively impact my desire to upgrade to the next version of Creative Suite!?

Get it fixed! If it negatively impacts the next update, get a few more people working on the next one!
Comments have been disabled for this article.
 
 
 
Top Stories
Vito Forte: A CIO for tough times
Fortescue Metals CIO talks vendor management and innovation.
 
Telstra shifts BigPond email to Windows Live
All data to be migrated to Microsoft cloud.
 
Vodafone Australia churn nears half a million for 2011
British joint owners 'not pleased'.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Would you be concerned about your business' email data being hosted offshore?

   |   View results
Yes
  84%
 
No
  16%
TOTAL VOTES: 243

Vote