NOD32 and Antivirus News
Threat and Security News

Adobe Acrobat JavaScript flaw exploit in the wild


Computer researchers at Johns Hopkins University have discovered a flaw within most recent version of Adobe's Reader and Acrobat software applications that could allow hackers to take control of vulnerable systems.

"Adobe categorizes this as an critical issue and recommends affected users update their installations," Adobe said in an advisory today.

There are reports that the exploit is in the wild, which both Adobe and security firm Secunia appear to be taking seriously.

The problem affects Acrobat and Reader versions 7.0.9 and earlier, as well as versions 8.0 through 8.1.2. Adobe disclosed the vulnerability on Monday in conjunction with the release of a security update for the current version, which is 8.1.2.

Users of version 7.1 are not affected by the vulnerability, and Adobe says Acrobat and Reader 9 which are due out in July are also immune.

According to a security bulletin by SecurityFocus, user input is not sanitized correctly. Essentially, an attacker could launch code remotely, which would in turn allow him to take control of an affected system.

More specifically, the problem is related to an input validation issue with JavaScript usage in either product. Indeed, JavaScript can be embedded in PDF files, so a JavaScript problem need not necessarily be browser-based.

SecurityFocus said the issue could be related to another earlier reported flaw late last month which involved a remote denial-of-service issue. At the time it was not known if code execution would be possible. That flaw affected similar versions of Adobe Reader.

By Ed Oswald, BetaNews

Original Story



NOD32 AntiVirus Products    Products    NOD32 FAQs    FAQs    Buy NOD32 AntiVirus Online    NOD32 4 Students    NOD32 Student and non-profit Discounts    NOD32 4 Non-Profit    NOD32 online purchase    Buy NOD32 Online    nod32 anti-virus

BETTERANTIVIRUS.COM℠ is a US based reseller of Eset Software's NOD32 Solutions
BETTERANTIVIRUS.COM℠ and it's contents is Copyright © - Web Your Business Inc.
BETTERANTIVIRUS.COM℠ & Web Your Business™ are trademarks of Web Your Business Inc.
ESET®, NOD32, ESET Antivirus, Smart Security® Trademark of ESET, LLC
All rights reserved by their respective owners.