Hackers love to exploit PDF bugs, says researcher
Last month's Adobe Reader vulnerability now under attack, says F-Secure and Microsoft
Computerworld - Hackers adore Adobe Reader, and have pushed it into first place as the software most often exploited in targeted attacks, a Finnish security company said today.
Helsinki-based F-Secure also urged users to update to the newest version of Reader to protect themselves against new attacks taking advantage of a vulnerability patched just three weeks ago.
According to F-Secure, 61% of the nearly 900 targeted attacks it's tracked in the first two months of 2010 exploited a vulnerability in Reader, Adobe's popular PDF viewer. By comparison, Microsoft's Word was exploited in just 24% of the attacks, and bugs in its Excel spreadsheet and PowerPoint presentation maker were leveraged only a combined 14% of the time.
Reader's slice of the targeted attack "market" climbed from 29% in 2008 to almost 50% last year, but at its pace so far this year, exploits aimed at Adobe's software are on track to account for nearly two out of every three attacks.
Microsoft's portion of targeted attack exploits, meanwhile, has steadily declined. Last year, for example, Word, Excel and PowerPoint exploits accounted for approximately 51% of attacks aimed at specific individuals or organizations. In 2008, exploits of those three Microsoft Office applications made up 71% of all targeted attacks.
Word, Excel and PowerPoint accounted for only 39% of all attacks so far this year, F-Secure said.
Targeted attacks can be disastrous to victimized companies and organizations. Google, for instance, was one of scores of Western corporations hit late last year and early this year by targeted attacks thought to originate from China. In Google's case, the attacks, which exploited a then-unpatched bug in Internet Explorer 6 (IE6), made off with company secrets. Intel was also attacked in January, but the chip maker has denied any connection between what hit its network and the Google-China attacks.
Earlier this week, the U.S. Federal Deposit Insurance Corporation (FDIC) said that hackers stole more than $120 million in just three months from small businesses' banking accounts, in some cases using malware carried by targeted attacks.
Adobe said it wasn't surprised at F-Secure's data. "Given the relative ubiquity and cross-platform reach of many of our products, Adobe has attracted -- and will likely continue to attract -- increasing attention from attackers," said spokeswoman Wiebke Lips in an e-mail.
She also urged users to update to the newest versions of Reader and other Adobe products. "The majority of attacks we are seeing are exploiting software installations that are not up-to-date on the latest security updates," she said.
F-Secure and Microsoft echoed Lips' recommendation, as both have discovered in-the-wild attacks exploiting a vulnerability Adobe patched less than a month ago.
On Feb. 16, Adobe issued an emergency update for Reader and Acrobat to patch a pair of flaws, including one tagged as CVE-2010-0188 in the Common Vulnerabilities and Exposures (CVE) database. Microsoft reported that bug to Adobe via its Microsoft Vulnerability Research Program (MSVR), where the company's security researchers submit flaws they find in third-party software to the programs' makers.
F-Secure's claim that Reader leads the exploit pack isn't the first time that a security company has awarded Adobe dubious honors. Last month, ScanSafe of San Bruno, Calif. said that malicious PDF files comprised 80% of all exploits at the end of last year.
The most up-to-date editions of Adobe Reader, 9.3.1 and 8.2.1, can be downloaded using links on Adobe's security site.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer or subscribe to Gregg's RSS feed
. His e-mail address is gkeizer@ix.netcom.com.
Security Alert
- Whoops! Microsoft leaks patch info four days early
- Researcher raps Apple for not blocking stolen SSL certificates
- Mac OS X can't properly revoke dodgy digital certificates
- Hackers may have stolen over 200 SSL certificates
- Apache patches Web server DoS vulnerability
- Google one of many victims in SSL certificate hack
- Hackers stole Google SSL certificate, Dutch firm admits
- Spike in mobile malware doubles Android users' chances of infection
- Microsoft patches critical Outlook drive-by bug
- 9 security suites: maximum protection, minimum fuss
Read more about Security in Computerworld's Security Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts
