New Adobe Reader, Acrobat Vulnerability Comes Under Attack

執筆者
Brian Prince
Brian Prince
Published: Oct 9, 2009
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Adobe is warning users about a critical vulnerability in versions of Adobe Reader and Acrobat that is being exploited in targeted attacks.

While little information has been made available about the exact nature of the vulnerability, it has been described by VUPEN Security as a memory corruption error. According to the advisory from VUPEN, the bug can be exploited remotely to compromise a vulnerable system.

Though the bug is known to affect Adobe Reader and Acrobat versions 9.1.3 and earlier on Windows, Mac and Unix systems, the exploit found in the wild is only targeting Windows.

“Adobe plans to resolve this issue as part of the upcoming Adobe Reader and Acrobat quarterly security update, scheduled for release on October 13,” blogged David Lenoe of the Adobe Product Security Incident Response Team. “Adobe Reader and Acrobat 9.1.3 customers with DEP (Data Execution Prevention) enabled on Windows Vista will be protected from this exploit.”

Adobe’s products have become a favorite target of attackers, most likely due to the prevalence of the company’s PDF reader and Adobe Flash Player. In response Adobe opted to change its patching process, aligning the release of security updates with Microsoft’s Patch Tuesday. The company also began reviewing legacy code as part of its development process when it updated its software.

As a workaround for this specific exploit, users can disable JavaScript. However, Adobe pointed out that a variant could be created that does not rely on JavaScript, so users should keep their antivirus definitions up-to-date.

Johannes Ullrich, a researcher with the SANS Institute, said users can also clean PDF documents by converting them into another format, such as Postscript, and then back into PDF.

“However, this is not 100 percent certain to remove the exploit and you may infect the machine that does the conversion as it will likely still use the vulnerable libraries to convert the document,” he blogged. “But the likelihood of this happening is quite low.”

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。