«
»


PDF: Beware

Posted by Brian Gallutia on Apr 7, 2010

adobe_logoElinor Mills with CNET News reports on the up-and-coming dangers facing Adobe PDF documents and those who utilize the format.

According to the report, PDF files could be used to spread malware to clean PDF files stored on a target computer running Adobe Acrobat Reader or Foxit Reader software.

Jeremy Conway, product manager at NitroSecurity, created a proof of concept for an attack in which malicious code is injected into a file on a computer as part of an incremental update, but which could be used to inject malicious code into any or all PDF files on a computer.

The attack requires the user of the computer to allow the code to be executed by agreeing to it via a dialog box. However, the attacker could at least partially control the content of the dialog box that appears to prompt the user to launch the executable and thus use social engineering to entice the computer user to agree to execute the malware, said Conway.

The good news is that both Adobe and Foxit have provided solutions / fixes to remedy the exploit.  Please take a moment to update your PDF reader software to insure that you and your business are not exposed to this potential threat.

Adobe Reader: http://get.adobe.com/reader/

Foxit Reader: http://www.foxitsoftware.com/downloads/index.php

Leave a Reply

You must be logged in to post a comment.