Adobe vulnerability exploits are mounting

Share this article:

A new and previously unknown exploit toolkit exclusively targets Adobe's PDF format.

According to a blog on the company's TrustedSource site, Secure Computing's Anti-Malware Research Labs has identified a toolkit dubbed the “PDF Xploit Pack.”

The blog entry says: “Typical functions like caching the already infected users are deployed by this toolkit on the sever side. Whenever a malicious PDF exploit is successfully delivered, the victim's IP address is remembered for a certain period of time. During this ‘ban time' the exploit is not delivered to that IP again, which is another burden for incident handling.”

The exploit joins other toolkits that have been enhanced with PDF exploits, such as one called the “El Fiesta” toolkit. But other analysts feel that any rise in overall PDF exploits may be coming from older, more entrenched attack kits, notably Neosploit.

“Based on the statistics we're analyzing right now, extrapolating it onto the Neosploit code base, and looking at two months of history, the rise in the exploitation of PDF vulnerabilities can definitely be attributed to Neosploit,” said Ian Amit, director of security research, Aladdin Knowledge Systems.

“El Fiesta distribution is very limited," he added, "and anecdotal evidence seems to indicate that the large number of PDF attacks cannot be directly attributed to PDF Xploit Pack or El Fiesta."

A patch for these exploits is available from Adobe, but, as Amit noted, “Not everyone patches quickly – and these attacks are continuing to be successful.”

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

Email promises free pizza, ensnares victims in Asprox botnet instead

Email promises free pizza, ensnares victims in Asprox ...

Cloudmark came upon an email that offers free pizza, but clicking on the link to get the coupon ends with victims being ensnared in a botnet.

Report: most orgs lacking in response team, policies to address cyber incidents

In its Q3 threat intelligence report, Solutionary learned that 75 percent of organizations it assisted had no response team or policies and procedures to address cyber incidents.

Flash redirect campaign impacts Carnegie Mellon page, leads to Angler EK

Flash redirect campaign impacts Carnegie Mellon page, leads ...

Malwarebytes found that, since early July, thousands of sites had been targeted in the campaign.