IT Security & Network Security News & Reviews - eWeek



Adobe Reader, Acrobat Security Vulnerability Patch Coming as Attacks Continue




Adobe Systems plans to release a patch for a zero-day vulnerability in Adobe Reader and Acrobat that has come under attack. This is the second critical security vulnerability Adobe has promised users it will fix in the coming weeks.

Adobe Systems is prepping a patch for a zero-day bug affecting its Reader and Acrobat software for release by Jan. 12.

The vulnerability is considered critical by Adobe and impacts the latest versions of Adobe Reader and Acrobat for Windows, Macintosh and Unix systems. Earlier editions are affected as well. The company has not released much information about the bug, but it is known to be under attack via malicious PDF files.

If exploited, the vulnerability could cause a crash or allow an attacker to execute code. According to Adobe and security researchers from the SANS Institute and The Shadowserver Foundation, users in search of a fix can disable JavaScript. Customers using Microsoft DEP (Data Execution Prevention) are at reduced risk in certain configurations. With the DEP mitigation in place, the impact of this exploit has been reduced to a denial of service, according to Adobe.

"There are reports that this vulnerability is being actively exploited in the wild … Adobe recommends that you keep your anti-malware software and definitions up-to-date and monitor releases from your vendor about this issue," Adobe Security Program Manager David Lenoe wrote on the company's Product Security Incident Response Team blog Dec. 15.

Adobe has said it will patch another vulnerability in January as well. That bug impacts Adobe Illustrator CS4 and CS3, and can be exploited to execute code via a malicious Encapsulated PostScript file in Illustrator. Proof-of-concept exploit code has already been published on the Web.







 
 
>>> More IT Security & Network Security News & Reviews Articles          >>> More By Brian Prince
 

FEATURED SPONSOR MESSAGE

Start the New Year with business intelligence—it’s a smart move

Join us on February 1 for an encore rebroadcast at either 5 am or 12 noon EST and discover how business intelligence (BI) supports companies in uncertain business and economic climates. Get expert advice on how to create a strategy that fits your organization's needs and budget and see how quickly it can pay for itself.

Click Here

Brought to you by


eweek digital



Advertisement
 
APPLY FOR A FREE 
SUBSCRIPTION BELOW:

>Try digital eWEEK
>Renew today
>Subscription help
>More FREE Subscriptions
First Name:Last Name:
Title:Company:
Address:City:
State:Zip Code:
Email:
eWEEK Quick LInks