Adobe Systems has released a security fix to address eight major vulnerabilities in version 8.12 of its free Adobe Reader application. The flaw was first reported to Adobe five months ago.
Core Security Technologies on Tuesday issued an advisory disclosing the vulnerability, which could affect millions of individuals and businesses that use the popular PDF file-viewing software. Specifically, CoreLabs engineers discovered attackers could exploit Adobe Reader to gain access to vulnerable systems by using a specially crafted PDF file with malicious JavaScript content.
“As with many of today’s ubiquitous client-side applications, the sheer complexity of Adobe Reader creates a broad surface for potential vulnerabilities and, in this case, Adobe’s inclusion of a fully fledged JavaScript engine introduces the same types of implementation bugs commonly found in such sophisticated client-side programs,” said Ivan Arce, Core’s CTO.
Exploring the Flaw
Core discovered the Adobe flaw while investigating the feasibility of exploiting a vulnerability previously disclosed in Foxit Reader. Researchers concluded that Adobe carried the same flaw.
Researchers initially thought the flaw was not exploitable in Adobe Reader because the software maker used two structured exception handlers. However, further digging uncovered the possibility of exploitation by bypassing a command to the print function.
“It’s worth noting that the bug was discovered while investigating a previously disclosed and similar problem in another PDF-viewer application, highlighting the manner in which common implementation mistakes are frequently shared among multiple vendors,” Arce said.
Successful exploitation of the vulnerability requires that users open a maliciously crafted PDF file. When a victim opens the file, he or she also unknowingly opens the door to attackers to gain access to vulnerable systems and assume the privileges of a user running Acrobat Reader. Adobe Reader version 9, released in June 2008, is not vulnerable to the problem.
In addition to the security update Adobe released, users…