On CBS.com: You a Survivor Fan?Play Survivor Fantasy
BNET Business Network:
BNET
TechRepublic
ZDNet

March 25th, 2009

Foxit PDF Reader being exploited in the wild

Posted by Ryan Naraine @ 8:53 am

Categories: Anti Virus, Arbitrary Code Execution, Browsers, Data theft, Denial of Service (DoS), Exploit code, Malware, Patch Watch, Pen testing, Responsible disclosure, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: Software, Malware, Exploit, Foxit, Spyware, Adware & Malware, Cyberthreats, Security, Viruses And Worms, Ryan Naraine

Adobe isn’t the only PDF software maker facing in-the-wild malware attacks.

Just weeks after the availability of patches for critical security flaws in the popular FoxIt Reader, there is word that malicious hackers are already targeting unpatched versions of the software.

According to Symantec’s Sean Hittel:

  • On March 20, our honeypots began detecting exploits for the Foxit PDF reader. Although it is not clear if this specific attacker intentionally wanted to target users of the Foxit Reader who had installed and not updated their software, or if the exploit was simply added to the attack toolkit when it became public, users should nonetheless review their installations to ensure that they are not vulnerable to this attack. Foxit has fixed all known security vulnerabilities, and you can review their security bulletins here.

[ SEE: Secunia finds 'highly critical' Foxit Reader Flaw ]

Hittel said the FoxIt exploits are exploiting these known vulnerabilities and have been fitted into an exploit toolkit that serves a variety of software exploits.

As always, if you have FoxIt Reader installed on your machine, upgrade to FoxIt 3.0 immediately.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 4 Talkback(s)
My own reasoning on this is:
All software has vulnerabilities, and those weaknesses will be exploited if the software is popular.

For me, I'll still prefer Foxit to Adobe's own reader just because of all the effort require... (Read the rest)
Posted by: D. W. Bierbaum Posted on: 03/27/09 You are currently: a Guest | | Terms of Use
Exploits not successful on PDF-XChange  bugmenot2 | 03/25/09
Latest version of Foxit allows Javascript to be disabled.  D. W. Bierbaum | 03/27/09
RE: Foxit PDF Reader being exploited in the wild  hbracer | 03/25/09
My own reasoning on this is:  D. W. Bierbaum | 03/27/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here