Adobe warned its users of active attacks exploiting a critical vulnerability in Adobe Reader and Acrobat 9.1.3 on Windows, Mac OS X and Unix.
Adobe says it will address the critical Reader and Acrobat vulnerability in a security update that it plans to release Oct. 13. Adobe maintains that thus far, the active exploits are limited to "targeted attacks" aimed at Reader and Acrobat 9.1.3 on Windows.
The upcoming Adobe patch is the second security update for both Reader and Acrobat this quarter.
While the vulnerability isn't dependent upon JavaScript, Adobe said in its security advisory that users might be able to mitigate the flaw by disabling the JavaScript function until a patch is released. Adobe also recommended that users keep antivirus products up to date. Meanwhile, Adobe Reader and Acrobat 9.1.3 customers with DEP enabled on Windows Vista are protected against attacks exploiting the vulnerability, Adobe said.
SANS Institute researcher Johannes Ullrich said in a blog that Adobe users could also "clean" PDF documents by converting them into an alternative format, such as PostScript, and then turning them back into a PDF.
"However, this is not 100 percent certain to remove the exploit and you may infect the machine that does the conversion, as it will likely still use the vulnerable libraries to convert the document. But the likelihood of this happening is quite low," Ullrich said.
Adobe said it is collaborating with several antivirus and security vendors in order to address the security vulnerabilities.
Until the issue is resolved, users can monitor the latest information on the Reader and Acrobat flaw at the Adobe Product Security Incident Response Team blog.
|
|
Symantec's Code Red: The Law Enforcement/Anonymous E-Mail Exchange Law enforcement officials negotiated via e-mail for more than two weeks with an Anonymous group member trying to extort $50,000 from Symantec to keep stolen product code off the Internet. |
|
|
How To Sell IT Security Services To Your Customers Cyberattacks can cost a business thousands, even millions, of dollars, and can deal a death blow to some. Here's how IT solution providers can help guard against malicious attacks. |
|
|
Cybersecurity Experts: What They Know Could Scare You A recent report based on interviews with security experts in government, business and academia finds more than half in agreement that a worldwide arms race is taking place in cyberspace. |
- Insider Threats: The Next Frontier for Security Resellers and SMBs
- Complete Security and Your Bottom Line: Sophos, Value and the Channel
- Tough Threats, Tougher Security: How You Can Leverage New Solutions To Combat A “Targeted Attack” Landscape
- Dark Clouds Ahead: Why the Mid-Market Needs To Ramp Up Cloud Security and How You Can Help Them Get There
