Adobe Discusses PDF Attack as Foxit Adds Warning | eWeek

Adobe Discusses PDF Attack as Foxit Adds Warning

Written By
Brian Prince
Brian Prince
Apr 1, 2010
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Foxit Software plans to follow Adobe Systems’ lead and add a dialog box giving users a heads-up about a new attack tactic involving malicious PDF files.

The security issue was uncovered by Didier Stevens, an IT security consultant with Contraste Europe, who discovered a way to get PDF viewers such as Adobe Reader and Foxit Reader to execute embedded executables using a launch action triggered when the PDF file is opened.

In Adobe Reader, the situation is mitigated by a warning that pops up and forces the user to click open before the executable is run. However, Foxit currently allows the embedded executable to run without either a warning or user interaction.

“After receiving word of a recent security concern, the Foxit development team immediately looked into the issue, confirmed the risk and resolved the situation quickly,” the company said in a statement. “Foxit expects to release a new version of Foxit Reader with this fix on April 2, 2010.

“To address the specific problems outlined, Foxit has added a warning dialog box that will pop up when a PDF file is opened with Foxit Reader, asking the user to agree to execute or not,” the company continued. “This solution adds a layer of safety yet maintains Foxit Reader’s compliance with current PDF standards.”

Adobe has said its warning box offers users sufficient protection, though Stevens has said he found a way to partially alter the warning in the dialog box as seen here in pictures on his blog. Ideally, Stevens told eWEEK March 31, the launch action feature should be disabled.

An Adobe spokesperson said the company is discussing the situation, but did not indicate if any further action would be taken.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.