Adobe Reader, Acrobat Security Vulnerability Patch Coming as Attacks Continue

Adobe Reader, Acrobat Security Vulnerability Patch Coming as Attacks Continue

Written By
Brian Prince
Brian Prince
Dec 16, 2009
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Adobe Systems is prepping a patch for a zero-day bug affecting its Reader and Acrobat software for release by Jan. 12.

The vulnerability is considered critical by Adobe and impacts the latest versions of Adobe Reader and Acrobat for Windows, Macintosh and Unix systems. Earlier editions are affected as well. The company has not released much information about the bug, but it is known to be under attack via malicious PDF files.

If exploited, the vulnerability could cause a crash or allow an attacker to execute code. According to Adobe and security researchers from the SANS Institute and The Shadowserver Foundation, users in search of a fix can disable JavaScript. Customers using Microsoft DEP (Data Execution Prevention) are at reduced risk in certain configurations. With the DEP mitigation in place, the impact of this exploit has been reduced to a denial of service, according to Adobe.

“There are reports that this vulnerability is being actively exploited in the wild … Adobe recommends that you keep your anti-malware software and definitions up-to-date and monitor releases from your vendor about this issue,” Adobe Security Program Manager David Lenoe wrote on the company’s Product Security Incident Response Team blog Dec. 15.

Adobe has said it will patch another vulnerability in January as well. That bug impacts Adobe Illustrator CS4 and CS3, and can be exploited to execute code via a malicious Encapsulated PostScript file in Illustrator. Proof-of-concept exploit code has already been published on the Web.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.