ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Adobe PDF Reader zero-day under attack

By | December 6, 2011, 12:49pm PST

Summary: According to a warning from Adobe, the attacks have been observed in the wild against Windows users running Adobe Reader version 9.4.6. An emergency fix is coming next week.

Unknown hackers are exploiting a zero-day vulnerability in Adobe’s PDF Reader software to launch “limited, targeted attacks” against high-value Windows users.

According to a warning from Adobe, the attacks have been observed in the wild against Windows users running Adobe Reader version 9.4.6.  Details on the attacks and targets are not known at this time.

The company plans to ship an emergency patch for Adobe Reader and Acrobat 9.x for Windows “no later than the week of December 12, 2011.”

The vulnerability is also present in Adobe’s newer Reader X software but because there are anti-exploitation roadblocks in that version, the company is in no rush to release Reader X updates to thwart this wave of attacks.follow Ryan Naraine on twitter

“The reason for addressing this issue quickly for Adobe Reader and Acrobat 9.4.6 for Windows is simple: This is the version and platform currently being targeted. All real-world attack activity, both in this instance and historically, is limited to Adobe Reader on Windows. We have not received any reports to date of malicious PDFs being used to exploit Adobe Reader or Acrobat for Macintosh or UNIX for this CVE (or any other CVE),” according to Adobe security chief Brad Arkin.

Arkin says that focusing this release on just Adobe Reader and Acrobat 9.x for Windows also allows Adobe to ship the update much earlier. “We are conscious of the upcoming holidays and are working to get this patch out as soon as possible to allow time to deploy the update before users and staff begin time off. Ultimately the decision comes down to what we can do to best mitigate threats to our customers,” Arkin added.

Arkin also pleaded with Adobe users to upgrade to the latest and greatest versions:

I’d like to take this moment to encourage any remaining users still running Adobe Reader or Acrobat 9.x (or worse, older unsupported versions) to PLEASE upgrade to Adobe Reader or Acrobat X. We put a tremendous amount of work into securing Adobe Reader and Acrobat X, and, to date, there has not been a single piece of malware identified that is effective against a version X install. Help us help you by running the latest version of the software!

Adobe rates this a “critical” issue that currently haunts Adobe Reader X (10.1.1) and earlier versions for Windows and Macintosh, Adobe Reader 9.4.6 and earlier 9.x versions for UNIX, and Adobe Acrobat X (10.1.1) and earlier versions for Windows and Macintosh.

“This vulnerability (CVE-2011-2462) could cause a crash and potentially allow an attacker to take control of the affected system,” Adobe warned.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
35
Comments

Join the conversation!

Just In

sdfsdf
jywhy888 7th Mar
Wholesale Binoculars Wholesale Mirror http://www.chinawholesaletown.com/wholesale-Vase/ Promotional Gifts
Wholesale Clothing Wholesale Flag http://www.chinawholesaletown.com/wholesale-Wine-Set/ Ruler
Wholesale Scale Computer Accessories http://www.chinawholesaletown.com/wholesale-Poncho-Raincoat/ Automotive Products
Wholesale Whistle Wholesale Scale http://www.chinawholesaletown.com/wholesale-Pen/ Clothes Rack
Consumer Electronics Cleaner Products http://www.chinawholesaletown.com/wholesale-Sport-Support/ Bag
Coin Bank Photo Frame http://www.chinawholesaletown.com/wholesale-Garden-Decorations/ Gift Box
Bottle Opener Wholesale Mobile Phone http://www.chinawholesaletown.com/wholesale-Kitchenware/ Pedometer
Electrical Gifts Wholesale Socks http://www.chinawholesaletown.com/wholesale-Golf-Items/ Name Card Holder
Electroluminescent Wholesale Gift Bags http://www.chinawholesaletown.com/wholesale-Solar-Products/ Fishing Supplies
Promotional Items Wholesale Swimming Products http://www.chinawholesaletown.com/wholesale-Clap-Hands/ Flash Gift
Wholesale Magnifier Gift Box http://www.chinawholesaletown.com/wholesale-Tape-Measure/ Golf Products
Money Bank Tape Measure http://www.chinawholesaletown.com/wholesale-Health-Care-Products/ Album
Wholesale USB Products China Wholesale http://www.chinawholesaletown.com/wholesale-Tag---lable/ Manicure Set
Sport Support Products Wholesale Towel http://www.chinawholesaletown.com/wholesale-Gift-Bags/ Stress Ball
Wholesale Helmet Wholesale Dartboard http://www.chinawholesaletown.com/wholesale-Home-Appliances/ Scale
Home Appliances Wholesale Vase http://www.chinawholesaletown.com/wholesale-USB-Flash-Drive/ Glasses
Wholesale Calculator Wholesale Album http://www.chinawholesaletown.com/wholesale-Vocal-Concert-Products/ Shoe
Silicone Products Heating Products http://www.chinawholesaletown.com/wholesale-Ruler/ Lady Beauty Care
Wholesale Mirror Bottle Opener http://www.chinawholesaletown.com/wholesale-Baby-Suppliers/ Promotional Items
Wholesale Keychain Wholesale Compressed Products http://www.chinawholesaletown.com/wholesale-Audio-Video-Equipment/ Mug
Digital Photo Frame Wholesale Bag http://www.chinawholesaletown.com/wholesale-Giveaway-Material/ Solar Products
Wholesale Compressed Products Crystal Gifts http://www.chinawholesaletown.com/wholesale-Playing-Card/ Racks
Wholesale Vuvuzela Coin Bank http://www.chinawholesaletown.com/wholesale-Puzzle/ Stationery
Wholesale Banner Wholesale Clap Hands http://www.chinawholesaletown.com/wholesale-Radio/ Calculator
Wholesale Knife Wholesale Bracelet http://www.chinawholesaletown.com/wholesale-Banner---Flag/ Flashlight
Giveaway Material Wine Set http://www.chinawholesaletown.com/ Badge
Manicure Set Garden Decorations http://www.chinawholesaletown.com/wholesale-Tellurion/ Umbrella
Wedding Favors Wholesale iPod iPhone http://www.chinawholesaletown.com/wholesale-Earphone/ T-Shirts
Wholesale Halloween Gift Men Beauty Care http://www.chinawholesaletown.com/wholesale-Book-Light/ Pen Holder
Wholesale Speakers Pen Holder http://www.chinawholesaletown.com/wholesale-Racks/ Furniture
Wholesale Jewelry Wholesale Tableware http://www.chinawholesaletown.com/wholesale-Pom-Poms/ Knife
Wholesale Apron Wholesale Furniture http://www.chinawholesaletown.com/wholesale-Lighting/ Bangle
Wholesale Pen Money Bank http://www.chinawholesaletown.com/wholesale-Album/ Christmas Gifts
Voice Recorder Wholesale Kitchenware http://www.chinawholesaletown.com/wholesale-Mat/ Cleaner Products
Wholesale Badge Advertising Material http://www.chinawholesaletown.com/wholesale-Stuffed-Animals/ Vase
Wholesale USB Flash Drive Wholesale Bookmark http://www.chinawholesaletown.com/wholesale-Banner---Flag/ Money Clip
Sport Items Wholesale Ruler http://www.chinawholesaletown.com/wholesale-Flashlight/ Eye Mask
0 Votes
+ -
Good article.
Joe.Smetona 6th Dec
Recent versions appear to be working better.
And more importantly, why don't they just push old new major versions through the update mechanisms of the old ones?

Bill O'Reilly says "you can't explain that".
@Joe_Raby : old versions are needed because there are applications (that may not be able to be upgraded yet) that are built to integrate at some level or another with specific versions of either Acrobat or Acrobat reader. Corporate use requirements can be a far cry from an individual user's requirements.
0 Votes
+ -
@Joe_Raby Because some people might not be able to run the new versions, and Adobe decided that just because they can't run the latest and greatest, that doesn't mean they should be left twisting in the wind.

Also, as mihondo says, corporate environments might not be using the latest version, so it makes sense to keep the previous versions secure as well.
0 Votes
+ -
sdfsdf
jywhy888 7th Mar
Wholesale Binoculars Wholesale Mirror http://www.chinawholesaletown.com/wholesale-Vase/ Promotional Gifts
Wholesale Clothing Wholesale Flag http://www.chinawholesaletown.com/wholesale-Wine-Set/ Ruler
Wholesale Scale Computer Accessories http://www.chinawholesaletown.com/wholesale-Poncho-Raincoat/ Automotive Products
Wholesale Whistle Wholesale Scale http://www.chinawholesaletown.com/wholesale-Pen/ Clothes Rack
Consumer Electronics Cleaner Products http://www.chinawholesaletown.com/wholesale-Sport-Support/ Bag
Coin Bank Photo Frame http://www.chinawholesaletown.com/wholesale-Garden-Decorations/ Gift Box
Bottle Opener Wholesale Mobile Phone http://www.chinawholesaletown.com/wholesale-Kitchenware/ Pedometer
Electrical Gifts Wholesale Socks http://www.chinawholesaletown.com/wholesale-Golf-Items/ Name Card Holder
Electroluminescent Wholesale Gift Bags http://www.chinawholesaletown.com/wholesale-Solar-Products/ Fishing Supplies
Promotional Items Wholesale Swimming Products http://www.chinawholesaletown.com/wholesale-Clap-Hands/ Flash Gift
Wholesale Magnifier Gift Box http://www.chinawholesaletown.com/wholesale-Tape-Measure/ Golf Products
Money Bank Tape Measure http://www.chinawholesaletown.com/wholesale-Health-Care-Products/ Album
Wholesale USB Products China Wholesale http://www.chinawholesaletown.com/wholesale-Tag---lable/ Manicure Set
Sport Support Products Wholesale Towel http://www.chinawholesaletown.com/wholesale-Gift-Bags/ Stress Ball
Wholesale Helmet Wholesale Dartboard http://www.chinawholesaletown.com/wholesale-Home-Appliances/ Scale
Home Appliances Wholesale Vase http://www.chinawholesaletown.com/wholesale-USB-Flash-Drive/ Glasses
Wholesale Calculator Wholesale Album http://www.chinawholesaletown.com/wholesale-Vocal-Concert-Products/ Shoe
Silicone Products Heating Products http://www.chinawholesaletown.com/wholesale-Ruler/ Lady Beauty Care
Wholesale Mirror Bottle Opener http://www.chinawholesaletown.com/wholesale-Baby-Suppliers/ Promotional Items
Wholesale Keychain Wholesale Compressed Products http://www.chinawholesaletown.com/wholesale-Audio-Video-Equipment/ Mug
Digital Photo Frame Wholesale Bag http://www.chinawholesaletown.com/wholesale-Giveaway-Material/ Solar Products
Wholesale Compressed Products Crystal Gifts http://www.chinawholesaletown.com/wholesale-Playing-Card/ Racks
Wholesale Vuvuzela Coin Bank http://www.chinawholesaletown.com/wholesale-Puzzle/ Stationery
Wholesale Banner Wholesale Clap Hands http://www.chinawholesaletown.com/wholesale-Radio/ Calculator
Wholesale Knife Wholesale Bracelet http://www.chinawholesaletown.com/wholesale-Banner---Flag/ Flashlight
Giveaway Material Wine Set http://www.chinawholesaletown.com/ Badge
Manicure Set Garden Decorations http://www.chinawholesaletown.com/wholesale-Tellurion/ Umbrella
Wedding Favors Wholesale iPod iPhone http://www.chinawholesaletown.com/wholesale-Earphone/ T-Shirts
Wholesale Halloween Gift Men Beauty Care http://www.chinawholesaletown.com/wholesale-Book-Light/ Pen Holder
Wholesale Speakers Pen Holder http://www.chinawholesaletown.com/wholesale-Racks/ Furniture
Wholesale Jewelry Wholesale Tableware http://www.chinawholesaletown.com/wholesale-Pom-Poms/ Knife
Wholesale Apron Wholesale Furniture http://www.chinawholesaletown.com/wholesale-Lighting/ Bangle
Wholesale Pen Money Bank http://www.chinawholesaletown.com/wholesale-Album/ Christmas Gifts
Voice Recorder Wholesale Kitchenware http://www.chinawholesaletown.com/wholesale-Mat/ Cleaner Products
Wholesale Badge Advertising Material http://www.chinawholesaletown.com/wholesale-Stuffed-Animals/ Vase
Wholesale USB Flash Drive Wholesale Bookmark http://www.chinawholesaletown.com/wholesale-Banner---Flag/ Money Clip
Sport Items Wholesale Ruler http://www.chinawholesaletown.com/wholesale-Flashlight/ Eye Mask
0 Votes
+ -
I don't use Adobe Reader. Do you?
0 Votes
+ -
@hawkeye96 Nope. Foxit all the way.
0 Votes
+ -
@statuskwo5 i second this
@statuskwo5

Not anymore Foxit has become just as bloated recently, as well as multiple hijacks.. (home page, tool bars, etc)...
0 Votes
+ -
@statuskwo5

Right on! You don't have to load the excess baggage (tool bars, etc)
0 Votes
+ -
@hawkeye96
Yes I use Adobe Reader, and the security features in Reader 10 are one of the big reasons. Does your PDF reader have sandboxing? All components opt into ASLR?
@hawkeye96 Yes, I use it.
0 Votes
+ -
RE: Adobe PDF Reader zero-day under attack
brittonburton@... 9th Dec
@hawkeye96

Nah I stopped using that buggy mess over a year ago, Foxit loads faster and you don't have to install its optional plugins, such as the offered toolbar, etc.

With Adobe they force all that other worthless junk, Adobe Air, Speed Launcher, Arm and other stuff onto you even if you tell it not to include those things. I personally don't see a need to have parts of a PDF viewer loading when my OS loads, that only serves to slow boot time down and has little to no use in a practical way. Shame on Adobe for the bloatware and an unnecessarily slow loading software. Now only if I could find a replacement for Flash Player.
0 Votes
+ -
"I???d like to take this moment to encourage any remaining users still running Adobe Reader or Acrobat 9.x..."

Interesting statement...'any remaining users', not good for PR, but, are there any?

I've been using Foxit Reader (and uninstalled the Adobe Reader bloatware) since it was first released. It has to be 10 times faster (probably 20) to view a pdf.
(I just hate those site that 'force' you to use it)
0 Votes
+ -
@scudrunner
sorry, if adobe is slowing your pc down then its time for a new pc buddy... the resource usage is practically obsolete... so how it can be slow, i wouldnt understand
0 Votes
+ -
RE: Adobe PDF Reader zero-day under attack
michaellashinsky@... Updated - 7th Dec
@mad-doggie

If Adobe products are constantly insecure to the point where Adobe is updating one of its products every week, and constantly bloated to the point where a new PC is required to run them, shouldn't we just do away with Adobe products and make due without the vulnerable and bloated software? I am still using a 2.6 GHz P4, and it is still faster than my internet connection. I do not need a faster PC at this point in my life. I am not going to upgrade to accommodate Adobe's bloatware, nor should I be expected to.

Seriously, think about your reasoning. If Firestone started making solid lead tires, are you going to buy a new car with a bigger engine to push them around, or are you going to not use solid lead tires? I choose not to use solid lead tires. I also choose not to use Adobe products that I can do without. I use Foxit whenever I can, and hope I see the day when Flash is replaced with html5. (The constant updating is pissing me off!)

(PS I just threw the name Firestone out there. I have no beef with them. Insert any manufacturer.)
@scudrunner

A website cannot Force you to use anything, simply download the PDF and open it in whatever reader you like.
0 Votes
+ -
RE: Adobe PDF Reader zero-day under attack
michaellashinsky@... 7th Dec
@Bozzer

Yeah, about that, many financial websites just don't work with Foxit, and the workarounds aren't a good option at work. I might be able to do it, but I cannot expect my users to.
0 Votes
+ -
What?!?
thx-1138_@... Updated - 6th Dec
Heavens forbid! Adobe having a zero day vulnerability? Has to be a misprint? A dreadful reporting error?

(...said with more than just a hint of cynical sarcasm)
0 Votes
+ -
A dreadful reporting error?
Agnostic_OS 7th Dec
@thx-1138_@...
Unfortunately not!
But don't worry I'm confident that Adobe will soon get the PDF Reader software back to its fine, swift, stability that it's always been the hallmark of this customer-centric company...

...oops back to the real world!
0 Votes
+ -
Adobe 10 reader chaged all my Icons to the Adobe graphic. I uninstalled Adobe and my Icons returned to normal. Removed every trace of Adobe reader and tried to re install several times and the same problem resulted. So I found FOXIT and it has a lot of great features.
0 Votes
+ -
Good Lord. Not again. Oh the Humanity!
Dietrich T. Schmitz * Your Linux Advocate 6th Dec
nt
0 Votes
+ -
PDF XChange Viewer is the best
RelaxWalk 6th Dec
It's even better than Foxit. PDF XChange viewer is free and has tab interface. And most important of all, resume the document as they were left, and allow to override the zoom factor. It is so smart compared to Acrobat Reader I wonder if Acrobat had won the Reader code from a lottery and doesn't know what to do with it.
0 Votes
+ -
Bloat
forrestgump2000@... 6th Dec
Of course everybody with Reader needs to have a 3D rendering component!
0 Votes
+ -
RE: Adobe PDF Reader zero-day under attack
michaellashinsky@... 7th Dec
@forrestgump2000@...

Yeah, about the bloat... Adobe wanted to be just like Microsoft, ...so they made their software bloated and vulnerable.
0 Votes
+ -
Propped Up//It Cheats
roger andre 6th Dec
Adobe also throw in their speed launcher to the windows start up set to try and make it look nippy! Very happy with foxit....it's a happier windows machine without adobe reader.
0 Votes
+ -
Adobe reader for the mac is a 68MB download, before installation. You can get complete operating systems smaller than that. There's absolutely no excuse for this bloatware, I shudder to think of the sloppy unnecessary code that's sitting in there.. specially when other PDF rendering apps clock in at just a few MB, and Mac's preview allows you to even edit PDFs. No wonder Adobe reader has so many bugs.
Reader X may or may not be more secure, but it's otherwise junk. And Foxit won't work with sites (like banks and utility companies) that generate account reports in PDF. They must use some special hooks into Adobe that don't exist in Foxit.
0 Votes
+ -
RE: Adobe PDF Reader zero-day under attack
mrefuman Updated - 7th Dec
@Vesicant

I work at an insurance company that uses similar hooks to generate policies. We tried foxit, and several other programs that wouldn't allow that funtionality. Man I hate having to run adobe acrobat. >.
0 Votes
+ -
How does the attack work?
talbott_chris@... 7th Dec
It would be nice if you included some details about the vulnerability. Am I safe if I simply avoid opening pdf files until the fix has been issued? Are other, non-Adobe readers vulnerable? If "no" to the second question, which alternate readers might be safe? Between this kind of reporting & the religious-wars comments, stories like this are worse than useless. Please try to be more helpful.
0 Votes
+ -
RE: Adobe PDF Reader zero-day under attack
michaellashinsky@... 7th Dec
@talbott_chris@...

I'm betting that its Adobe that isn't letting any details out.
0 Votes
+ -
RE: Adobe PDF Reader zero-day under attack
Rabid Howler Monkey Updated - 9th Dec
@talbott_chris@... The link to Adobe's warning provided in the article references a "U3D memory corruption vulnerability" and I would interpret this as a specially crafted U3D file embedded in a PDF document:

"Adobe Reader/Acrobat U3D Memory Corruption Vulnerability
http://secunia.com/advisories/47133/

Secunia says not to open untrusted PDF documents.

The Universal 3D (U3D) is a compressed file format standard for 3D computer graphics data and Adobe Acrobat and Adobe Reader (since version 7), Photoshop CS3, Poser 7, DAZ Studio and MeshLab all support U3D:

http://en.wikipedia.org/wiki/Universal_3D

The PDF 1.6 specification supports interactive 3D documents, including U3D, embedded in the PDF document:

http://en.wikipedia.org/wiki/Portable_Document_Format

According to the following link, Adobe's Reader, since version 7, is the only product that can interactively display 3d data:

http://wiki.jmol.org/index.php/File_formats/3D_PDF#Software_for_creating_or_viewing_3D_PDF

Do current software versions from Foxit Software and other alternative PDF reader providers support the PDF 1.6 specification, including U3D? And if they do, are they vulnerable? I don't know on both counts.

Edit: Disabling javascript, if supported, in one's PDF Reader app would also make it more difficult for the exploit to succeed:

http://blog.9bplus.com/analyzing-cve-2011-2462
0 Votes
+ -
ADOBE READER IS NOT A READER
mswift@... 7th Dec
If Adobe understood the meaning of the word "reader" we would not be having this discussion.
0 Votes
+ -
RE: Adobe PDF Reader zero-day under attack
michaellashinsky@... 8th Dec
@mswift@...

Yes! Thank you.
0 Votes
+ -
What's a high-value Windows user ?

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix