Microsoft helps Adobe block PDF zero-day exploit
Urges Windows users to deploy EMET 2.0 to stop attacks on Reader
Computerworld - Microsoft last Friday urged Windows users to block ongoing attacks against Adobe's popular PDF viewer by deploying one of Microsoft's enterprise tools.
Adobe echoed Microsoft's advice, saying the Enhanced Mitigation Experience Toolkit (EMET) would stymie attacks targeting Reader and Acrobat.
Called "scary" and "clever," the in-the-wild exploit went public last week when security researcher Mila Parkour reported it to Adobe after analyzing a rogue PDF document attached to spam. Adobe first warned users Wednesday of the threat, but at the time gave users no advice on how to protect themselves until a patch was ready.
Microsoft stepped in on Friday.
"The good news is that if you have EMET enabled ... it blocks this exploit," said Fermin Serna and Andrew Roths, two engineers with the Microsoft Security Response Center (MSRC) in an entry on the group's blog.
EMET, which Microsoft upgraded to version 2.0 earlier this month, is a stop-gap designed to keep older applications secure until companies upgrade to up-to-date, and theoretically safer, versions of those programs.
The tool lets IT administrators, and consumers willing to take the plunge, switch on several Windows defenses -- including ASLR (address-space layout randomization) and DEP (data execution prevention) -- for applications whose developers didn't turn them on by default.
The newest PDF exploit defeated Windows' DEP by leveraging a dynamic link library, or DLL, used by Adobe in both programs. Usually, ASLR prevents DEP bypassing, but according to researchers and Microsoft, the "icucnv36.dll" library doesn't have ASLR enabled. That gave attackers a way to sidestep both defenses.
Microsoft's Serna and Roths showed how to use EMET to switch on ASLR for Reader and Acrobat in Windows Vista, Windows 7, Server 2008 and Server 2008 R2, blocking the current exploit. A different tactic is needed to protect Windows XP and Server 2003 systems, which don't support what Microsoft called "mandatory ASLR."
Both Microsoft and Adobe admitted that they had had little time to test the impact of the EMET-based workaround. "Due to the time-sensitive nature of this issue, we have only been able to perform a cursory look at the functional compatibility of this mitigation," said Serna and Roths. "We recommend that you also test the mitigation in your environment to minimize any impact on your workflows."
Some researchers have blasted Adobe for poor programming practices, saying that its mistakes left Reader and Acrobat users at risk.
"This time Adobe gives a hand to the attacker," said Prevx researcher Marco Giuliani, talking about the failure to enable ASLR in icucnv36.dll. "Adobe could have easily prevented this type of exploit."
For others, the moment when Adobe launches its next version of Reader, which will include "sandboxing" technology to isolate application processes from one another and from the rest of the machine, won't come too soon.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Security for Virtualization Learn more.
- When Malware Goes Mobile: Causes, Outcomes and Cures Cybercriminals are increasingly setting their sights on smartphones and other mobile devices. Learn about platform-specific policies and strategies you can employ to protect...
- Case Study: Hospital Turns to Email Archiving Solution to Ensure Regulatory Compliances Read this case study to learn how a cloud-based email archiving solution enabled the hospital to meet government mandates and helps avoid thousands...
- Case Study: In-the-Cloud Email Service Replaces Three Point Products Read this case study for more information on a comprehensive in-the-cloud email service to help replace three point products.
- 3 Reasons Why Sepaton is the World's Fastest Backup Solution Leading analyst, Storage Switzerland learns how Sepaton backs up and deduplicates massive data volumes while maintaining the industry's fastest performance - all in...
- Enterprise File Sharing: All You Need to Know Security. Scalability. Control. These are just some of the many benefits of enterprise cloud file-sharing that you'll discover in this KnowledgeVault, packed with... All Malware and Vulnerabilities White Papers | Webcasts