Tuesday, December 15, 2009

Serious Adobe PDF Exploit

A serious exploit of Adobe PDF files has been discovered and malicious PDF files are being detected on the Internet since December 11th or so.

There is no patch for this issue at this time and anti-virus applications are not yet able to detect the malware due to how it is packaged. 

The problem appears to be in a JavaScript function inside of Adobe.  If you know how, you can disable JavaScript in Adobe Reader.  (Edit – Preferences – JavaScript – uncheck Enable Acrobat JavaScript).  Note that this may mean some PDFs do not display or act correctly, but it will mitigate the current issue.  Once a patch has been released you can turn it back on if you want.

Of course you should be careful downloading any type of file from the Internet.  However, be extra careful with PDFs at the moment.  Once a patch is released, we will post another article here.

No comments:

Post a Comment