Sign in | Join United States - English [Change]
 Home > Insights 

This Blog

Syndication

Calendar

<October 2008>
SunMonTueWedThuFriSat
2829301234
567891011
12131415161718
19202122232425
2627282930311
2345678

CA Security Advisor Research Blog

Find out what our research team is saying about the latest security threats in the CA Security Advisor blog

Prevalence of Exploited PDFs

While the threat landscape has changed dramatically over the past years, attackers are becoming increasingly aggressive in exploring ways to get into users’ system. A spammed email with an EXE attachment no longer penetrates the wider network or users, now that most home users and enterprise networks have a certain level of awareness on information security. But, how about spamming an exploited file like a PDF?

The incidents of exploited PDF files are not isolated. Instead, there has been a consistent prevalence and recurrence of this threat. So, what are the vulnerabilities being exploited? Most of the malicious PDF files we see exploit a known buffer overflow vulnerability in the "Collab.collectEmailInfo()" function which can be found in the Adobe PDF Reader JavaScript engine. This vulnerability was discovered in February of this year and was related to CVE-2007-5659 and CVE-2008-0655.

As shown in the screenshot below, the malicious stream data contains JavaScript that attempts to attack vulnerable versions and thereafter execute its embedded shellcode. Attackers often reuse the exact code and only change its payload.

Another vulnerability being constantly exploited is URI (Uniform Resource Identifier) handling, where attackers misuse “mailto” in order to execute commands. Here’s the screenshot of the malicious object inside the PDF file and the command executed behind these strings:

This vulnerability was discovered in September 2007 and was referred to CVE-2007-5020. The interesting part here is that these vulnerabilities only exist in Adobe Reader and Acrobat 8.1.1 and earlier, which means updating to a latest version will protect users’ systems. Unfortunately, this doesn’t stop the attackers in continuously serving this threat.

CA products detects the malicious PDF file as PDF/Pidief and PDF/CVE-2007-5020!exploit.

Share this post: Email it! | bookmark it! | digg it! | reddit!

Comments

CA Security Advisor Research Blog said:

As mentioned in my previous post Prevalence of Exploited PDFs , over the past months CA ISBU has seen

November 10, 2008 6:22 PM

Leave a Comment

(required)  
(optional)
(required)  
Add

About Methusela Cebrian Ferrer

Methusela Cebrian Ferrer is a Senior Research Engineer with the CA Internet Security Business Unit (CA ISBU) based in Melbourne, Australia. Previous to CA, she spent 5 years on the antivirus service team and R&D group for Trend Micro Internet Security Labs. She also worked with antivirus and anti-Spyware software for PC Tools Research in Sydney, where she specialized in research and analysis of Mac OS X security threats. Her specialty is in security exploits and vulnerabilities on mobile and Mac platforms. She holds MCSE and MCSA Microsoft certifications and is an active member of AISA and ISSA organization, as well as various information security forums.
 
 
Page Tools