On TV.com: FAMILY GUY Special Finds New Sponsor
BNET Business Network:
BNET
TechRepublic
ZDNet

October 22nd, 2007

Adobe shuts backdoor in PDF Reader, some old versions still vulnerable

Posted by Ryan Naraine @ 12:33 pm

Categories: Botnets, Browsers, Data theft, Exploit code, Hackers, Microsoft, Patch Watch, Pen testing, Responsible disclosure, Spam and Phishing, Viruses and Worms, Vulnerability research, Windows Vista, Zero-day attacks

Tags: Adobe Systems Inc., Adobe PDF, Adobe Acrobat, Adobe Acrobat Reader, Microsoft Corp., Microsoft Windows, Operating Systems, Security, Software, Ryan Naraine

Adobe shuts backdoor in PDF Reader, some old versions still vulnerableAs promised earlier this month, Adobe has shipped a fix for the URI protocol handling vulnerability that left a backdoor open on Windows XP machines with Internet Explorer 7 installed.

The patch, rated “critical,” addresses multiple flaws in Adobe Reader and Acrobat that could allow an attacker to take complete control of a vulnerable system.

From Adobe’s advisory:

This issue only affects customers on Windows XP with Internet Explorer 7 installed. A malicious file must be loaded in Adobe Reader or Acrobat by the end user for an attacker to exploit these vulnerabilities.

[ SEE: Adobe confirms PDF backdoor, offers unsupported workaround ]

Adobe is strongly recommending that Windows users upgrade to Adobe Reader 8.1.1 or Acrobat 8.1.1 immediately.

It’s important to note that this patch only applies to some versions of the software. For instance, there are no patches yet for Adobe Reader 7.0.9 and Acrobat 7.0.9. Adobe says those fixes will come “at a later date.”

[ SEE: MS Outlook flaw adds new twist to URI handling saga ]

In the meantime, the temporary workaround is to disable the “mailto:” option in Acrobat, Acrobat 3D and Adobe Reader by modifying the application options in the Windows registry (see instructions here).

Microsoft is also planning to ship an update to address this issue.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 9 Talkback(s)
trolling for dollars
Come now; lets not confuse a religious turf war with facts. (Read the rest)
Posted by: hines@... Posted on: 10/24/07 You are currently: a Guest | | Terms of Use
Adobe Reader "Check for Updates" doesn't update!  killerbunny | 10/22/07
this happened on the last update also  Narr vi | 10/23/07
All I can say is...  BillyG_n_SC | 10/22/07
Fixed or not?  wdlists@... | 10/23/07
You're not fixed...  Technocrat@... | 10/23/07
RE: Adobe shuts backdoor in PDF Reader, some old versions still vulnerable  rebelxhardcore | 10/23/07
Uh..  Wolfie2K3 | 10/23/07
trolling for dollars  hines@... | 10/24/07
Acrobat 8.1.1 Reader Update works!  Wolfie2K3 | 10/23/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More