Adobe Acrobat
Details about the Adobe Reader vulnerability were published in late September

Attack code targets unpatched Adobe Reader flaw

Time running out for Adobe to patch 'critical' vulnerability

Written by Tom Sanders in California

A security researcher has published a proof-of-concept exploit for a known vulnerability in Adobe Reader.

The researcher, known only as 'Cyanid-E', unveiled his creation in a posting to the Full Disclosure security mailing list on Tuesday.

The vulnerability has been confirmed on a fully patched Windows XP system running Adobe's Acrobat Reader 8.1 and Internet Explorer 7.

Details about the vulnerability were published in late September on the GNU Citizen blog.

The blog did not post proof-of-concept code at the time because it expected Adobe to be slow to respond. Proof-of-concept code can easily be turned into live attack code, and the publication could have put users at risk.

The proof-of-concept demonstrates the exploit by opening the calculator application when users open a specially crafted PDF file.

Although the code is harmless, criminals could easily modify it to install malware or recruit a system into a botnet.

Adobe acknowledged the flaw earlier this month and published a workaround that protects users.

A spokesperson for Adobe told vnunet.com that the company is aware of the proof-of-concept and is preparing to release an update within the next two weeks.

Adobe recommends users to implement the workaround and use extreme caution when viewing and downloading "unsolicited communications".

Tags:

Further reading

Adobe admits to critical software flaws

Reader and Acrobat vulnerable in IE7 on Windows XP   More...

Adobe buys Buzzword online word processor

Acquisition of Virtual Ubiquity strengthens online apps   More...

Adobe puts 'iSpin' on mobile Flash

New version of player guns for the iPhone crowd   More...

Adobe Flash Player 9.0.124

Latest version of the Flash player   More...

Related articles

Attackers target PDF vulnerability

Beware the bill or invoice pdf   More...

Adobe admits to critical software flaws

Reader and Acrobat vulnerable in IE7 on Windows XP   More...

Microsoft patches eight 'critical' holes

August update covers four web browsing risks   More...

Attackers feast on Real Player flaw

Real promises to patch hole as soon as possible   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement