With Adobe Reader Zero-Day Circulating, Patching for Older Bug Lags | eWeek

With Adobe Reader Zero-Day Circulating, Patching for Older Bug Lags

Written By
Brian Prince
Brian Prince
Apr 29, 2009
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

While Adobe Systems works to patch the recent zero-day bug discovered in its Adobe Reader and Acrobat products, new data from Qualys suggests many users are so behind in patching that hackers needn’t feel rushed to exploit the flaw.

According to Qualys, there has been no significant reduction in the number of machines vulnerable to APSA09-01, a zero-day bug patched by Adobe more than a month ago.

“If this trend continues to persist for the Adobe Reader vulnerabilities, which it has in all 2008 and as demonstrated in Laws 2.0 [PDF], attackers don’t need to rush anymore; they can take their time in figuring out the best way to get an infected PDF file into their victims,” opined Wolfgang Kandek, CTO of Qualys.

It is a common scenario. In Microsoft’s Intelligence Report for the second half of 2008, Microsoft found that 91.3 percent of attacks against Microsoft Office exploited a single vulnerability that was patched more than two years ago (CVE-2006-2492). For a multitude of reasons, patching for both enterprises and home users lags after fixes, leaving holes open for hackers.

In the case of the latest Adobe bug, the vulnerability stretches across all supported versions of Adobe Acrobat and Reader on the Windows, Mac and Unix platforms. Proof-of-concept exploit code for the flaw, described as the “Adobe Reader ‘getAnnots()’ JavaScript Function Remote Code Execution Vulnerability” by SecurityFocus, is already circulating on the Internet.

While users wait for a patch, Adobe suggests they disable JavaScript in the PDF reader. To do so, follow the instructions on the Adobe security blog.

“We are working on a development schedule for these updates and will post a timeline as soon as possible,” David Lenoe wrote on the Adobe security blog. “We are currently not aware of any reports of exploits in the wild for this issue.”

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.