Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    May 2012
    S M T W T F S
    « Apr    
     12345
    6789101112
    13141516171819
    20212223242526
    2728293031  
  • About Us
    Malware Blog > Adobe Acrobat/Reader getIcon() Vuln Exploit in the Wild

    Cyber criminals have now updated their PDF exploits to include the getIcon() vulnerability (CVE-2009-0927). We currently detect this as TROJ_PIDIEF.OE.

    As usual, we highly encourage users to update now to the latest versions of Adobe Acrobat and Adobe Reader (if you haven’t yet). Reading the security advisory by Adobe closely, we see that this issue was previously fixed in version 8.1.3 but not for version 9.0:

    The Adobe Reader and Acrobat 9.1 and 7.1.1 updates resolve an input validation issue in a JavaScript method that could potentially lead to remote code execution. This issue has already been resolved in Adobe Reader 8.1.3 and Acrobat 8.1.3. (CVE-2009-0927)

    PATCH NOW.

    References:





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    5 Responses to “Adobe Acrobat/Reader getIcon() Vuln Exploit in the Wild”

    Trackbacks

    1. cybasurfa (cybasurfa)
    2. SecurityGeek (Security Geek)
    3. spywarevoid (spywarevoid)
    4. hackertweets (Hacker Tweets)
    5. Adobe Acrobat/Reader getIcon() Vulnerability Exploit in the Wild | Kaspersky Labs USA


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice