On BNET: Online porn struggles for profits
BNET Business Network:
BNET
TechRepublic
ZDNet

October 9th, 2009

New Adobe PDF flaw under attack; Patch coming Tuesday

Posted by Ryan Naraine @ 8:03 am

Categories: Adobe, Anti Virus, Arbitrary Code Execution, Browsers, Complex Attacks, Data theft, Denial of Service (DoS), Exploit code, Hackers, Malware, Patch Watch, Pen testing, Research, Responsible disclosure, Spam and Phishing, Spyware and Adware, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: Adobe Systems Inc., Adobe PDF, Adobe Acrobat, Flaw, Adobe Acrobat Reader, Attack, Microsoft Windows, Security, Viruses And Worms, Operating Systems

Adobe has confirmed a critical, unpatched vulnerability in its PDF Reader/Acrobat software is being exploited by malicious attackers.

The vulnerability affects Adobe Reader and Acrobat 9.1.3 and earlier versions on Windows, Macintosh and UNIX.  Adobe described the in-the wild attacks as limited and targeted, suggesting PDF documents rigged with exploits are being attached to e-mails and sent to business targets.

The exploit only targets Adobe Reader and Acrobat 9.1.3 on Windows.

Adobe’s advisory offers some mitigations:

Adobe Reader and Acrobat 9.1.3 customers with DEP enabled on Windows Vista will be protected from this exploit. Disabling JavaScript also mitigates against this specific exploit, although a variant that does not rely on JavaScript could be possible. In the meantime, Adobe is also in contact with anti-virus and Security vendors regarding the issue and recommends users keep their anti-virus definitions up to date.

[SEE: MS Patch Tuesday heads-up: 13 bulletins, 34 vulnerabilities ]

Adobe plans to ship a patch for this flaw next Tuesday, the same day Microsoft will release 13 bulletins to cover 34 Windows vulnerabilities.

This Adobe Patch Day is part of the company’s Adobe Reader and Acrobat quarterly security update schedule.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 30 Talkback(s)
Honey rarely answers my questions...
...I'm starting to think he doesn't like me.

"Get your facts first, then you can distort them as you please." - Mark Twain... (Read the rest)
Posted by: 914four Posted on: 10/14/09 You are currently: a Guest | | Terms of Use
Note to all Knuckleheads....  htotten | 10/09/09
Thankfully...  914four | 10/13/09
Why announce at all? Just fix the thing  chrome_slinky@... | 10/09/09
They need to warn the admins that take care of many systems.  phatkat | 10/09/09
You can't fix, test & release in seconds...  wright_is | 10/12/09
RE: New Adobe PDF flaw under attack; Patch coming Tuesday  Daddy Tadpole | 10/09/09
RE: New Adobe PDF flaw under attack; Patch coming Tuesday  gertruded | 10/09/09
OS for on line work.  Agnostic_OS | 10/09/09
This is not a Windows flaw...  rx7racer | 10/09/09
Agreed  Agnostic_OS | 10/09/09
in-the-wild implementation is targeted for Windows  gertruded | 10/09/09
Windows is fine, actually  mechBgon | 10/09/09
Vista is soooo broken  seveprim@... | 10/09/09
Vista's default configuration  Agnostic_OS | 10/09/09
I was referring to Adobe's own remarks, actually  mechBgon | 10/09/09
Adobe's own remarks  Agnostic_OS | 10/10/09
Given that...  wright_is | 10/12/09
Why do they even have a version 9?  K B | 10/09/09
RE: New Adobe PDF flaw under attack; Patch coming Tuesday  Bilmekanikeren | 10/09/09
Linux is exploitable too  honeymonster | 10/10/09
Any proof?  Wintel BSOD | 10/12/09
So, Honey, can you please explain...  914four | 10/13/09
Yes, I'd like to know that myself...  Wintel BSOD | 10/13/09
Honey rarely answers my questions...  914four | 10/14/09
RE: New Adobe PDF flaw under attack; Patch coming Tuesday  joseph_boese@... | 10/10/09
getting rid of the bloated insecure inferior  Agnostic_OS | 10/10/09
just install Foxit pdf reader instead  joseph_boese@... | 10/10/09
Which is what I use on Linux, anyway...  Wintel BSOD | 10/12/09
It's not perfect either...  s_southern | 10/13/09
We have standardized on MacBooks for the sales force and consulting arm  914four | 10/13/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here