McAfee has discovered a vulnerability in Adobe’s Reader program that allows people to track the usage of a PDF file.
“Recently, we detected some unusual PDF samples,” McAfee’s Haifei Li said in a blog post. “After some investigation, we successfully identified that the samples are exploiting an unpatched security issue in every version of Adobe Reader.”
The affected versions of Adobe Reader also include the latest “sandboxed” Reader XI (11.0.2).
McAfee said that the issue is not a “serious problem” because it doesn’t enable code execution, however it does permit the sender to see when and where a PDF file has been opened.
This vulnerability could only be dangerous if hackers exploited it to collect sensitive information such as IP address, internet service provider (ISP), or even the victim’s computing routine to eventually launch an advanced persistent threat (APT).
McAfee said that it is unsure who is exploiting this issue or why, but have found the PDFs to be delivered by an “email tracking service” provider.
The vulnerability works when a specific PDF JavaScript API is called with the first parameter having a UNC-located resource.
“Adobe Reader will access that UNC resource. However, this action is normally blocked and creates a warning dialog,” Li said. “The danger is that if the second parameter is provided with a special value, it changes the API’s behavior. In this situation, if the UNC resource exists, we see the warning dialog.
“However, if the UNC resource does not exist, the warning dialog will not appear even though the TCP traffic has already gone.”
McAfee said that it has reported the issue to Adobe and is waiting for their confirmation and a future patch. Adobe wasn’t immediately available for comment at the time of writing.
“In addition, our analysis suggests that more information could be collected by calling various PDF Javascript APIs. For example, the document’s location on the system could be obtained by calling the Javascript “this.path” value,” Li added.
Source
Tags: Adobe Flash exploit, Adobe Reader, Adobe Reader XI, android, Android 2.2.2, Android Market Place, Android Market Security Tool, Apache License, apps, CA, Cellular, China, code, command-and-control server, CVE-2011-0609, cybercriminals, devices, DroidDream, exploid, Freemont, Google, Hackers, handsets, hardware, IMEI, IMSI, infected devices, International Mobile Equipment Identity, International Mobile Subscriber Identity, malicious code, malware, MCAfee, mobile OS, mobiles, operating systems, owners, patches, phones, projects, rageagainstthecage, Security, security specialists, security tools, servers, SIM cards, SMS, Software, stolen information, Symantec, technology, text messaging, third-party applications, tools, USA, users, vendors, version, Zero Day
Hackers have found a way to exploit Adobe Flash Player by using a zero-day vulnerability by using Microsoft Excel documents that was confirmed by Adobe yesterday. Adobe representatives that they will not be able to patch Flash until next week. Therefore, if you use Flash you are on your own until next week. Read More….
Tags: Adobe Flash exploit, advantages of using a consultant, android, Android 2.2.2, Android Market Place, Android Market Security Tool, Apache License, apps, best Internet Phone Service, CA, Cellular, Chicago Computer Help Desk, Chicago Computer Services, Chicago Data Center, Chicago Internet Providers, chicago PC Technician, Chicago Telcom Audits, Chicago VoIP, China, cloud computing, Cloud Computing Chicago, code, command-and-control server, computer consultant, Computer Consultants, Computer Help Desk, Computer Install, computer network services, computer programmers, computer Serurity, Computer Services, Computer Technician in Chicago, Computer Technician Outsourcing, CVE-2011-0609, cybercriminals, data centers, Desktop Services, devices, DroidDream, email services, exploid, Freemont, Google, Hackers, handsets, hardware, Help Desk Services, hosted exchange, IMEI, IMSI, infected devices, International Mobile Equipment Identity, International Mobile Subscriber Identity, IT Audits, IT Outsourcing, IT support services, linksys routers, malicious code, malware, managed IT services, Microsoft Excel Exploited, mobile OS, mobiles, Network Design, network management, Network Optimization, Network routers, Network Services, network solutions, network support services, online data backup, operating systems, owners, patches, PC repairs, phones, projects, rageagainstthecage, Routers, Security, security specialists, security tools, Server Management, servers, SIM cards, SMS, Software, stolen information, Symantec, technical support, technology, Telcom Audits, telephone auditing review, text messaging, The Syber Group, third-party applications, tools, USA, users, vendors, version, Virtual Computers, Virtual Machine, Virtualization, VoIP in Illinois, VoIP MPLS, voip office phone systems chicago, Windows Technician, Wireless Internet, Zero Day