Even as Adobe is touting the new sandbox (Protected Mode) in the newest version of its PDF Reader software, a security researcher says the company's implementation leaves significant "residual risk" for cyber-attackers to exploit.
According to Chris Greamo, a researcher at Invincea, the Adobe Reader X sandbox is definitely a step in the right direction but he argues that the implementation will not prevent attacks from accessing sensitive parts of a hijacked computer.
- Protected Mode will not prevent unauthorized read access to the file system or registry.
- Protected Mode will not restrict network access.
- Protected Mode will not prevent reading or writing to the clip board.
- Read and exfiltrate data from the registry and/or user’s file system
- Attack other machines and devices on the network
- Use Reader as a stepping stone to execute other exploits against the host system including exploits against kernel services
The sandbox, included in Adobe Reader X, is similar to the Google Chrome sandbox and Microsoft Office 2010 Protected Viewing Mode. Based on Microsoft’s Practical Windows Sandboxing technique, it is turned on by default and displays all operations in a PDF file in a very restricted manner.
The first sandbox implementation isolates all “write” calls on Windows 7, Windows Vista, Windows XP, Windows Server 2008, and Windows Server 2003. Adobe argues that this will mitigate the risk of exploits seeking to install malware on the user’s computer or otherwise change the computer’s file system or registry. In a future dot-release, the company plans to extend the sandbox to include read-only activities to protect against attackers seeking to read sensitive information on the user’s computer.
Invincea's Greamo believes the residual exposures left by Adobe’s Protected Mode are "significant" and can only be addressed by a more comprehensive solution that confines attacks against all Reader components, the shared libraries it uses, the kernel, and the network.
"With the release of Adobe Reader X, expect to see new vulnerabilities presented by this additional code to be discovered and exploited by the BlackHat community," he added.