Adobe's PDF vulnerability patched

Security researchers say Adobe's PDF vulnerability, which was fixed Tuesday, is more of a pressing issue than Microsoft's PowerPoint vulnerabilities fixed the same day.

Adobe issued Windows updates for Reader and Acrobat versions 7, 8 and 9 and Macintosh and Unix updates for versions 8 and 9 for a vulnerability in Reader and Acrobat. The company said updates for Adobe Reader and Acrobat 7 for Macintosh are scheduled to be available before the end of June, according to the security bulletin

The vulnerability, which relates to a JavaScript memory corruption error and garnered a "highly critical" rating from Secunia, affects all supported versions on the Windows, Macintosh and Linux platforms. Proof-of-concept code is circulating on the internet, but Adobe representatives said in early May they are not aware of any in-the-wild exploits.

The patch also addresses a second vulnerability in Adobe's Reader for Unix software. 

Microsoft issued a fix for 14 bugs in PowerPoint Tuesday, but researchers say Adobe's vulnerabilities are more pressing than Microsoft's.

Paul Henry, security and forensic analyst for Lumension told SCMagazineUS.com that it is important to remember that historically, files like Adobe PDF's or those in Word, Excel or PowerPoint have been great vehicles for targeted attacks because such attachments seem socially acceptable and are simply expected within corporate email.

The use of PDF files as a vehicle for the delivery of malware gives a hacker an added advantage, Henry said. It is anticipated that anti-virus vendors will create better signatures from the information contained within the patch to identify infected files. The bad guys, however, could simply start obfuscating the current exploit to try to capture any unpatched users.

Henry added that Lumension has found numerous Chinese web sites that were hosting malicious PDF files using the most current vulnerability, a contradiction of Adobe's position.

“Adobe has had a rash of patches come out lately and since Adobe is not covered by Windows update you have to find a way to roll out these patches in enterprises, making it more difficult to get the patches installed,” Eric Schultze, CTO, Shavlik Technologies told SCMagazineUS.com Tuesday.

Since Adobe documents are more common in business than PowerPoint documents, Schultze recommended  users should get the Adobe patch installed first.

Andrew Storms, director of security operations for nCircle told SCMagazineUS.com he agreed that Adobe's issues present a much greater risk to users than the PowerPoint bug.

More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.