Most Popular Stories
Events
- Register for The Security Standard 2010
September 13 - 14 — New York, NY - SharePoint Technology Conference
October 20 - 22 — Boston, MA - Northwestern University Master of Science in Information Systems (MSIS)
- Register for IT Roadmap Dallas 2010
September 14 — Dallas Convention Center
Sponsored Links
HOT TOPICS >> Q2 Earnings Roundup | Cloud Computing | Tablets | Security Vulnerabilities and Exploits
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- 5 Must Haves in your Information Management Strategy
- Cloud Computing: How To Make Your Own Silver Lining
- Durable Smart Devices for Mobile Field Forces: Selection and Evaluation Criteria
- The Shortcut Guide to Secure, Managed File Transfer
- Enterprise Digital Assistant Leverage in the Emerging Mobile Enterprise
We never sell or give away your contact information. Our reader's trust comes first.
New variant of PDF attack requires no user action
Researcher Didier Stevens has discovered that the mere storing of a malicious PDF file could trigger an attack targeting a new flaw in Adobe's popular PDF file format. The new vector is possible on a machine with a vulnerable version of Adobe Reader or Acrobat, and where the target machine is running Windows Indexing Services. Windows Indexing Services is a feature that comes with Windows in order to index files in the system.
When Windows Indexing Services picks up an infected PDF file and a vulnerable version of Adobe Reader or Acrobat is running, the malware will be executed. This leads to what is known in security circles as a "privilege escalation."
Previously, Stevens had released proof-of-concept code that demonstrates how opening a malicious PDF file from Windows Explorer could be used to exploit a PC. However, the latest discovery is even more dangerous, considering that it does not require any user interaction at all. The problem here originates from a buffer overflow problem that Adobe is already aware of.
This particular bug can prove troublesome if not quickly addressed, due to the sheer ubiquity of the PDF file format. Users and administrators alike should upgrade to the fixed version of Adobe Reader and Acrobat 9 released earlier this week as soon as possible.
For more on this story:
- check out this article at DarkReading
Related Articles:
Adobe Reader bug allows access to user's local drive
Adobe Reader bug can trigger Firefox/Opera attack
Adobe to release Reader fix this week
Related Stories
- Red tape keeps Conficker on critical medical devices
- Is your VoIP network secure?
- Security meets adult content
- How to: Speed up Adobe Reader (Windows only)
- New PowerPoint flaw requires patching
- Symantec fighting suspect Vista security features
- BlackBerry Trojan hits the scene
- It's a show of vulnerabilities at Black Hat conference
- Cross-platform virus alarms experts
- Proof of concept attack highlights new weakness in PDF specification
Comments
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2010 FierceMarkets. All rights reserved. |
![]() |







