Zero-day PDF exploit affects Adobe Reader 11 and earlier versions, researchers say
Adobe is investigating the report, but has yet to confirm that the exploit bypasses the sandbox protection in Adobe Reader 10 and 11
IDG News Service - Researchers from security firm FireEye claim that attackers are actively using a remote code execution exploit that works against the latest versions of Adobe Reader 9, 10 and 11.
"Today, we identified that a PDF zero-day [vulnerability] is being exploited in the wild, and we observed successful exploitation on the latest Adobe PDF Reader 9.5.3, 10.1.5, and 11.0.1," the FireEye researchers said late Tuesday in a blog post.
The exploit drops and loads two DLL files on the system. One file displays a bogus error message and opens a PDF document that's used as a decoy, the FireEye researchers said.
Remote code execution exploits regularly cause the targeted programs to crash. In this context, the fake error message and second document are most likely used to trick users into believing that the crash was the result of a simple malfunction and the program recovered successfully.
Meanwhile, the second DLL installs a malicious component that calls back to a remote domain, the FireEye researchers said.
It's not clear how the PDF exploit is being delivered in the first place -- via email or over the Web -- or who were the targets of the attacks using it. FireEye did not immediately respond to a request for additional information sent Wednesday.
"We have already submitted the sample to the Adobe security team," the FireEye researchers said in the blog post. "Before we get confirmation from Adobe and a mitigation plan is available, we suggest that you not open any unknown PDF files."
The Adobe Product Security Incident Response Team (PSIRT) confirmed Tuesday in a blog post that it is investigating a report of a vulnerability in Adobe Reader and Acrobat XI (11.0.1) and earlier versions being exploiting in the wild. The risk to customers is being assessed, the team said.
In response to a request for a status update sent Wednesday, Heather Edell, Adobe's senior manager of corporate communications, said that the company is still investigating.
Sandboxing is an anti-exploitation technique that isolates a program's sensitive operations in a strictly controlled environment in order to prevent attackers from writing and executing malicious code on the underlying system even after exploiting a traditional remote code execution vulnerability in the program's code.
A successful exploit against a sandboxed program would have to leverage multiple vulnerabilities, including one that allows the exploit to escape from the sandbox. Such sandbox bypass vulnerabilities are rare, because the code that implements the actual sandbox is usually carefully reviewed and is fairly small in length compared to the program's overall codebase that could contain vulnerabilities.
Adobe added a sandbox mechanism to isolate write operations called Protected Mode in Adobe Reader 10. The sandbox was further expanded to cover read-only operations as well in Adobe Reader 11, through a second mechanism called Protected View.
- 10 Hot Big Data Startups to Watch
- 11 Unique Uses for Google Glass, Demonstrated by Celebs
- How to Export Your Google Reader Account
- How to Better Engage Millennials (and Why They Aren't Really so Different)
- Telltale signs of ATM skimming
- 20 security and privacy apps for Androids and iPhones
- Big screen con artists: 7 great movies about social engineering
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Enabling Ubiquitous Visibility in Virtualized Environments Enterprises are rapidly adopting virtualization for dynamic service delivery and service management agility. IT challenges already exist in virtual environments and will only...
- The Importance of Performance Management in Software-defined Networking Riverbed Technology and VMware have joined forces to help address these problems and make it easy to deploy and manage VXLAN overlay networks...
- Network Monitoring and Troubleshooting for Dummies The Network Monitoring and Troubleshooting for Dummies Book introduces you to common network performance management (NPM) issues and give you a new way...
- Firewall and IPS Deployment Guide Discover how to quickly deploy a full-service business network that is next-generation threat-ready. This comprehensive guide is based on best-practice design principles that...
- Live Webcast
Bring Mobile Innovation to your Enterprise. - With the mobility revolution well underway, CIO's and Line of Business owners are faced with the struggle to develop a winning mobile strategy.
- Bring Mobile Innovation to your Enterprise. With the mobility revolution well underway, CIO's and Line of Business owners are faced with the struggle to develop a winning mobile strategy.
- Dell Software This overview of Dell SonicWALL next-generation firewalls showcases how you can increase network security by scanning every packet without any compromises in network... All Networking White Papers | Webcasts
Rising salaries boost IT optimism, though not everyone is feeling upbeat. Our survey of 4,000+ IT workers shows who's riding the wave and why. Use our interactive tool and compare your own paycheck. Read more...