Most Popular Stories
- Rumor: iPad 3 will come with a quad-core A6 processor
- A rundown of Windows 8 features you should know about
- What are you anticipating the most in Windows 8?
- Content Marketing could be supplanting the traditional corporate blog
- Symantec drops warning against use of pcAnywhere, but questions remain
- New toolkit capable of bypassing Apple's FileVault 2 disk encryption
Events
- Gartner CIO Leadership Forum 2012
March 25-27 — Scottsdale, AZ - CIO Healthcare Summit
March 11-14 — Scottsdale, AZ - COMPTEL PLUS Spring 2012
April 15-18 — San Francisco, CA - CIO Summit
March 18- 21 — Miami, FL
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- The Top 4 Reasons Your Telecom Expense Management Provider Shouldn't Manage Your Wireless
- CSO White Paper - Desktop Virtualization: Empowering Information Security
- Green Doesn't Have to be Hard
- Ringing in Growth - How Service Bureau-based Outsourcing is a Win-Win Approach for Communications Service Providers
- Ensuring Cultural Adoption
New variant of PDF attack requires no user action
Researcher Didier Stevens has discovered that the mere storing of a malicious PDF file could trigger an attack targeting a new flaw in Adobe's popular PDF file format. The new vector is possible on a machine with a vulnerable version of Adobe Reader or Acrobat, and where the target machine is running Windows Indexing Services. Windows Indexing Services is a feature that comes with Windows in order to index files in the system.
When Windows Indexing Services picks up an infected PDF file and a vulnerable version of Adobe Reader or Acrobat is running, the malware will be executed. This leads to what is known in security circles as a "privilege escalation."
Previously, Stevens had released proof-of-concept code that demonstrates how opening a malicious PDF file from Windows Explorer could be used to exploit a PC. However, the latest discovery is even more dangerous, considering that it does not require any user interaction at all. The problem here originates from a buffer overflow problem that Adobe is already aware of.
This particular bug can prove troublesome if not quickly addressed, due to the sheer ubiquity of the PDF file format. Users and administrators alike should upgrade to the fixed version of Adobe Reader and Acrobat 9 released earlier this week as soon as possible.
For more on this story:
- check out this article at DarkReading
Related Articles:
Adobe Reader bug allows access to user's local drive
Adobe Reader bug can trigger Firefox/Opera attack
Adobe to release Reader fix this week
Related Stories
- New Trojan stymies cloud-based antivirus security
- Researchers bring attention to USB attack via Android phone
- Crackdown on Zeus banking scam unearths massive cybercrime outfit
- Proof of concept attack highlights new weakness in PDF specification
- Red tape keeps Conficker on critical medical devices
- How to: Speed up Adobe Reader (Windows only)
- How to make your Windows 7 system start faster
- Air Force drone control system now runs on Linux
- Developers flock to HTML5
- Big Patch Tuesday from Microsoft to kick off 2012
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




