Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    February 2012
    S M T W T F S
    « Jan    
     1234
    567891011
    12131415161718
    19202122232425
    26272829  
  • About Us
    Malware Blog > New Adobe Zero-Day Exploit

    Trend Micro threat analysts were alerted to the discovery of a zero-day exploit that affects Adobe Reader and Acrobat 9.1.3 and earlier versions (CVE-2009-3459). Trend Micro detects this as TROJ_PIDIEF.UO. This .PDF file contains an embedded JavaScript, which Trend Micro detects as JS_AGENTT.DT. This JavaScript is used to execute arbitrary codes in a technique known as heap spraying. In addition, there is a possibility that a future variant may be created that does not use JavaScript to exploit the said vulnerability.

    Based on our findings, the shellcode (that was heap sprayed) jumps to another shellcode inside the .PDF file. The said shellcode then extracts and executes a malicious file detected by Trend Micro as BKDR_PROTUX.BD. The said backdoor is also embedded in the .PDF file and not the usual file downloaded from the Web. Protux variants are known for their ability to provide unrestricted user-level access to a malicious user. Earlier variants of the Protux backdoor were seen to have been used as payload in previous attacks exploiting vulnerabilities in Microsoft Office files.


    Click Click
    Click

    As of this writing, Adobe has indicated that it will include this vulnerability in its upcoming security update release. Meanwhile, users are recommended to disable JavaScript in Adobe Acrobat/Reader to mitigate the said attack. To do this, they should follow these steps:

    1. Run Acrobat or Adobe Reader.
    2. Go to Edit > Preferences.
    3. Select JavaScript under the Categories tab.
    4. Uncheck the “Enable Acrobat JavaScript” option.
    5. Click OK.

    Users are also advised to patch their systems as soon as Adobe releases the security patch. Trend Micro protects users with the Smart Protection Network by detecting the said exploit.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    25 Responses to “New Adobe Zero-Day Exploit”

    Trackbacks

    1. ATENÇÃO, nova vulnerabilidad… - Edu Godinho Blog
    2. Adobe exploit puts backdoor on computers « GO IT WORLD | IT TECH | IT NEWS
    3. UnderForge of Lack » Blog Archive » 2009.10.10 月曜日
    4. TrendMicro (TrendMicro)
    5. mikerigsby (Mike Rigsby)
    6. LjTx (Lj (girl geek))
    7. TrendMicroBR (Trend Micro Brasil)
    8. egodinho (Edu Godinho)
    9. stevenabanks (Steven Banks)
    10. neop26 (Aben Samuel)
    11. [CNET] Adobe exploit puts backdoor on computers - Overclock.net - Overclocking.net
    12. CyberHades » Blog Archive » 0day en Adobe Reader y Adobe Acrobat
    13. Adobe exploit puts backdoor on computers : BizzRoot
    14. matrosov (Alexander Matrosov)
    15. opexxx (alex knorr)
    16. Adobe exploit puts backdoor on computers - Windows 7 Center Forums
    17. Keeping your OS patched isn’t enough | Social Nibble
    18. Keeping your OS patched isn’t enough | Open Source Blog
    19. Adobe Exploit puts Backdoor on Computers | Virus Experts - We Make Your Digital Life Secured
    20. Adobe, grave la falla di Acrobat « ThE_RaV[3]N Space
    21. New Adobe Zero-Day Exploit - Windows Help Forum
    22. Huge Patch Tuesday from Microsoft and Adobe « Smart Website Security
    23. Adobe Reader 9.2 and Acrobat 9.2 out, containing 29 security Fixes | WebKetu
    24. [パッチ] Adobe Reader/Acrobat 9.2 « UnderForge of Lack
    25. New Adobe Zero-Day Exploit – Security Threat Research News


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice