Categories: Security

New Zero-Day Acrobat Reader Vulnerability

On February 19th, Adobe confirmed reports that its version 9 software of Adobe Acrobat and Adobe Reader were vulnerable to buffer overflows that have allowed some companies to be targeted in spearphishing attacks.

Their announcement said:

A critical vulnerability has been identified in Adobe Reader 9 and Acrobat 9 and earlier versions. This vulnerability would cause the application to crash and could potentially allow an attacker to take control of the affected system. There are reports that this issue is being exploited.

Adobe is planning to release updates to Adobe Reader and Acrobat to resolve the relevant security issue. Adobe expects to make available an update for Adobe Reader 9 and Acrobat 9 by March 11th, 2009. Updates for Adobe Reader 8 and Acrobat 8 will follow soon after, with Adobe Reader 7 and Acrobat 7 updates to follow. In the meantime, Adobe is in contact with anti-virus vendors, including McAfee and Symantec, on this issue in order to ensure the security of our mutual customers.

McAffee’s Avert Labs Blog has screenshots of the buffer overflow in action here. They go on to say:

Needless to further remind everyone, zero-day attacks are the preferred choice of cyber criminals and will continue to be so in 2009. If the recent W32/Conficker.worm (MS08-087) and Exploit-XMLhttp.d (MS08-078, MS09-002) were not good enough to prove our point, here is another one.

As a reminder, the Better Business Bureau phishing scam successfully exploited many large companies last year by sending emails with malicious .PDF attachments to executives of those companies. And since there will not be a patch in place until Mid-March, you need to watch out which adobe files you choose to open.

Surf carefully and update your AV files.

Geeks are Sexy

Recent Posts

Costco’s Hot Dog Economics: Bun-derful Bargains or Frank-ly a Loss Leader?

https://youtu.be/twUK5YreLWk?si=SZGqB6HsbkYaGKyr Ever wondered why the price of Costco's legendary hot dogs has remained unchanged at…

15 mins ago

How logic alone may prove that time doesn’t exist

StunningArt/Shutterstock Matyáš Moravec, University of St Andrews Modern physics suggests time may be an illusion.…

1 hour ago

RIP John Trimble: The Man Who Saved Star Trek from Cancellation

In a galaxy far, far away from the clutches of cancellation, a hero quietly worked…

3 hours ago

Today’s Hottest Deals: X-Men ’97 Magneto Premium Helmet, Bose QuietComfort Headphones, Apple Watch Series 9, Apple AirTag, and More!

For today’s edition of “Deal of the Day,” here are some of the best deals…

3 hours ago

Nat 20 [Comic]

[Source: @colmcomics]

4 hours ago

Sweet Talk or Cringe-Worthy: The Science of Cheesy Pet Names

https://youtu.be/KJpYWOJNVGY?si=vsu_6JYvYYO9VBpH Ever wondered why we use those adorable yet cringey words for our loved ones?…

4 hours ago