Adobe issued a security advisory Thursday about vulnerabilities in its Adobe Reader and Acrobat products. The company labeled the vulnerabilities critical, reflecting the highest level of severity, and indicated that software updates will be available on Tuesday, Oct. 13.
A number of Adobe products and all platforms are involved. The update will cover Adobe Reader 9.1.3, Acrobat 9.1.3, Adobe Reader 8.1.6, and Acrobat 8.1.6 for Windows, Macintosh and UNIX. The updates also will cover Adobe Reader 7.1.3 and Acrobat 7.1.3 for Windows and Macintosh.
If unpatched, malicious code carried in downloaded PDF documents can be executed and damage can be caused by viruses, Trojans or other malware if the file is opened by the user. Attacks have been seen in the wild targeting Windows using Adobe Reader and Acrobat 9.1.3. The advisory said that computers with Data Execution Prevention (DEP) enabled on the Windows Vista operating system are not impacted.
The alert also said the variants observed in the field are neutralized if JavaScript is disabled. However, the company warned that the base vulnerability may be used for exploits that don’t involve JavaScript.
So Far, Limited Impact
Brad Arkin, director of product security and privacy for Adobe, said the company has information on “about a half-dozen” attacks. He said next Tuesday’s security update is the second of two on the company’s schedule. The first was released June 9. A response to the attacks has been folded into the second update, he said.
Ryan Naraine, a security evangelist for Kaspersky Labs, said the attacks seem to be aimed at corporate and business types. “This is a big deal for two reasons. One is that it is not patched yet, and two is that there already are attacks happening. That means that malicious hackers got hold of this vulnerability before Adobe did.”
Targeting Adobe
Researchers agree that Adobe is a…