Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Adobe Issues Reader, Acrobat Security Updates to Stave Off Attacks

    Written by

    Brian Prince
    Published February 21, 2013
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Adobe Systems pushed out emergency updates Feb. 20 to quell attacks targeting Reader and Acrobat on Windows.

      The updates patch two vulnerabilities—CVE-2013-0640 and CVE-2013-0641—that can be exploited to allow an attacker to hijack a vulnerable system. According to Adobe, both bugs are being exploited in targeted attacks that try to trick Windows users into clicking on a malicious PDF file delivered to them by email. The vulnerabilities themselves, however, impact both Windows and Mac users.

      “Adobe recommends users apply the updates for their product installations,” the company said in an advisory, describing the vulnerabilities as critical.

      The patch follows a warning from security firm FireEye last week that attackers were launching malicious PDFs at Windows users in a zero-day attack. According to FireEye, when the vulnerability was successfully exploited, it would deploy two Dynamic Link Library (DLL) files.

      The first would show a fake error message and open a decoy PDF document. The second file deployed a callback component that talked to a remote Internet domain. The attackers were able to bypass the Adobe Reader sandbox, FireEye’s senior director of security researcher, Zheng Bu, told eWEEK last week.

      “The JavaScript embedded in the crafted PDF is highly obfuscated using string manipulation techniques,” FireEye researchers noted in a blog post Feb. 13. “Most of the variables in the JavaScript are in Italian. The JavaScript has version checks for various versions of Adobe Reader … and it creates the appropriate shellcode based on the version found.

      “The payload involved in this exploit ultimately installs what appears to be a first-stage downloader in the form of a DLL posing as a “language bar add-in,” using the registry key “HKCUSoftwareMicrosoftCTFLangBarAddIn” to persist after reboot,” the FireEye team continued. “It further attempts to legitimize this disguise in its file properties.”

      This is not the first out-of-band patch this month for Adobe, which said last year it was aligning its patch releases with Microsoft’s Patch Tuesday. Earlier this month, the company issued updates for critical vulnerabilities impacting Flash Player that, if exploited, could enable an attacker to hijack a vulnerable system. The company also issued another update to address vulnerabilities in both Flash Player and Shockwave Player.

      Adobe, however, has also tried to make strides in terms of its security in recent years, revamping not only its patch release cycle but also its development procedures. Still, that hasn’t stopped Reader from being a popular target among criminal hackers.

      “Adobe Reader is ubiquitous; it’s almost as important to patch as the Microsoft operating system patches, in some cases more so,” said Ross Barrett, senior manager of security engineering at Rapid7. “With Microsoft you can choose not to use Internet Explorer, but until today, you were likely using Adobe Reader with IE, Chrome or Firefox. I say until today because Firefox 19 just came out with its own, built-in, non-Adobe PDF reader.”

      Switching to another PDF reader, however, may only provide a semblance of relief from attacks in the long run, said Alex Horan, senior product manager at Core Security.

      “Of course if everyone switches to Foxit, then so would the attackers,” he said. “But the one-time cost of switching your users to Foxit must be less than the ongoing cost of applying updates to Adobe Reader and the zero-day risk it constantly presents.”

      Brian Prince
      Brian Prince

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×