Sign in | Join United States - English [Change]
 Home > Insights 

This Blog

Syndication

Calendar

<November 2008>
SunMonTueWedThuFriSat
2627282930311
2345678
9101112131415
16171819202122
23242526272829
30123456

CA Security Advisor Research Blog

Find out what our research team is saying about the latest security threats in the CA Security Advisor blog

Yet Another Exploited PDF in the Wild

As mentioned in my previous post Prevalence of Exploited PDFs, over the past months CA ISBU has seen consistent, recurring attacks on malware explicitly designed to exploit PDF vulnerabilities – this mainly involves the 'Collab.collectEmailInfo()' function and misusing the URI 'mailto'. Today, another strain joins the group.

Adobe Security Bulletin released an update last week, fixing the critical vulnerability CVE-2008-2992 found in Adobe PDF Reader’s JavaScript engine. The flaw was specifically found in a weak implementation of JavaScript’s 'util.printf()' function, where an attacker can send a series of strings long enough to cause a stacked-based buffer overflow. An attacker can then execute arbitrary code on the system; unfortunately with the same level privileges as the user who’s running the vulnerable version of Adobe Reader.

A proof-of-concept code was immediately published on various channels displaying a good number of hits; almost immediately after this, attackers took advantage of the vulnerability, as shown in the latest exploited or trojanized PDF sample we received:

Example trojan exploiting the Adobe Reader and Adobe Acrobat PDF vulnerability

Example of files downloaded by PDF/Utilf.A

Adobe Reader 9 and Acrobat 9 are not affected by this vulnerability. However, users running Adobe Reader 8.1.2 and earlier versions should immediately update. Please see the relevant Adobe security bulletin:
http://www.adobe.com/support/security/bulletins/apsb08-19.htm

Furthermore, CA’s Anti-Virus solutions detect these malicious PDF files as PDF/Utilf and PDF/CVE-2008-2992!exploit.

Share this post: Email it! | bookmark it! | digg it! | reddit!

Comments

No Comments

Leave a Comment

(required)  
(optional)
(required)  
Add

About Methusela Cebrian Ferrer

Methusela Cebrian Ferrer is a Senior Research Engineer with the CA Internet Security Business Unit (CA ISBU) based in Melbourne, Australia. Previous to CA, she spent 5 years on the antivirus service team and R&D group for Trend Micro Internet Security Labs. She also worked with antivirus and anti-Spyware software for PC Tools Research in Sydney, where she specialized in research and analysis of Mac OS X security threats. Her specialty is in security exploits and vulnerabilities on mobile and Mac platforms. She holds MCSE and MCSA Microsoft certifications and is an active member of AISA and ISSA organization, as well as various information security forums.
 
 
Page Tools