SUBSCRIBE TO TMCnet
TMCnet - World's Largest Communications and Technology Community

CHANNEL BY TOPICS


QUICK LINKS




Adobe PDF Patches Combat Rising Exploits

SIP Trunking

Security Featured Article

February 17, 2010

Adobe PDF Patches Combat Rising Exploits

By David Sims
TMCnet Contributing Editor
Share

Timed to coincide with Adobe delivering the latest patches for its popular PDF viewer, a security firm said it reckons malicious Reader documents made up “80 percent of all exploits at the end of 2009.”
 
Industry observer Gregg Keizer reported that according to ScanSafe (News - Alert) of San Bruno, California, “vulnerabilities in Adobe’s Reader and Acrobat applications were the most frequently targeted of any software during 2009, with hackers’ PDF exploits growing throughout the year.”

 
The Inquirer’s Edward Berridge reported that Adobe “has released emergency updates to patch a pair of critical vulnerabilities in its popular PDF viewing and editing software.”
 
Adobe “ranked both bugs as critical,” Berridge said: “Last week we were told that the software outfit would issue rush patches for Adobe Reader and Adobe Acrobat.”
 
Over the course of 2009, Keizer says, the incidence of malicious PDF files increased -- accounting for 56 percent of all exploits tracked by ScanSafe in the first quarter of 2009, rising to above 60 percent in the second quarter, over 70 percent in the third and topping at 80 percent in the fourth quarter.
 
Saying the updating “tackles a brace of serious flaws,” The Register’s (News - Alert) John Leyden noted that “the cross-platform Reader and Acrobat update fixes a vulnerability in the domain sandbox of the PDF technology that opens the door to possible exploits, more specifically unauthorized cross-domain requests. In addition the update addresses a critical flaw that creates a mechanism for hackers to inject hostile code” onto vulnerable systems.
“PDF exploits are usually the first ones attempted by attackers,” Mary Landesman, a ScanSafe senior security researcher told Keizer, who said she was referring to the multi-exploit hammering that hackers typically give visitors to malicious Web sites. “Attackers are choosing PDFs for a reason. It’s not random. They’re establishing a preference for Reader exploits.”
 
Landesman confessed she wasn’t sure why it was increasing. “Perhaps they are more successful. Or maybe it’s because criminal attackers are human, too. We respond when we see a lot of people going after a particular product. We all want to go after that product, too. In the attacker arena, they might be thinking, ‘Gee, all these reports of Adobe Reader zero-days, maybe I should get in on them too.’”
 
In 2009, 107 Adobe vulnerabilities were logged into CVE, nearly double the 58 added in 2008 and almost triple the 35 reported in 2006, Landesman noted.

David Sims is a contributing editor for TMCnet. To read more of David’s articles, please visit his columnist page. He also blogs for TMCnet here.

Edited by Marisa Torrieri


+ Return to SIP Trunking Home
Comments powered by Disqus






Technology Marketing Corporation

2 Trap Falls Road Suite 106, Shelton, CT 06484 USA
Ph: +1-203-852-6800, 800-243-6002

General comments: [email protected].
Comments about this site: [email protected].

STAY CURRENT YOUR WAY

© 2024 Technology Marketing Corporation. All rights reserved | Privacy Policy