February 13, 2013

Happy happy joy joy

There is an exploit for PDF files -- from FireEye:
In Turn, It's PDF Time
We have found IE, Java, and Flash zero-days in a row in the past several months, and now it's PDF�s turn. Today, we identified that a PDF zero-day is being exploited in the wild, and we observed successful exploitation on the latest Adobe PDF Reader 9.5.3, 10.1.5, and 11.0.1.

Upon successful exploitation, it will drop two DLLs. The first DLL shows a fake error message and opens a decoy PDF document, which is usually common in targeted attacks. The second DLL in turn drops the callback component, which talks to a remote domain.
I started using the Foxit Reader about five years ago. The Adobe product is huge -- bloatware at its finest. Foxit is lean and speedy. Good stuff! Posted by DaveH at February 13, 2013 11:48 AM
Comments
Post a comment









Remember personal info?