Sponsored Community Message Browse Free. Go deeper with Full Access. Free visitors can browse public knowledge. Full Access unlocks participation, member areas, and an ad-free experience.

New Security Hole Found in Adobe Reader and Acrobat: Here is How to Enable Protection Against the Exploit-gctid73080

Started by Ajamu, Feb 14, 2013, 11:18 PM

Previous topic - Next topic
New Security Hole Found in Adobe Reader and Acrobat: Here is How to Enable Protection Against the Exploit



 A new security hole has been found for multiple versions of Adobe  Reader and Acrobat, so how do you protect your system until Adobe  releases a new update? Our quick tutorial today will show you how to do  just that with a quick tweak in the settings for Reader and Acrobat.

 Note: We are using Adobe Reader for our example here, but the same tweak applies to Acrobat as well.

 The goal of the tweak is to activate the Protected View Feature. Go to the Edit Menu, select Preferences, then look for the Security (Enhanced)  listing in the left hand column and click on it. Once that is done you  will see two levels of security that can be enabled under the Protected View heading. At a minimum you will want to select Files from potentially unsafe locations, but for maximum effect select the All files option. After making your selection go to the bottom of the window and click the OK Button. That is all there is to it!

 

 The Affected Adobe Software Versions Include:
 
'"
    n".self::process_list_items("'.str_replace('
    ', '', '
  • Adobe Reader XI (11.0.01 and earlier) for Windows and Macintosh
  • Adobe Reader X (10.1.5 and earlier) for Windows and Macintosh
  • Adobe Reader 9.5.3 and earlier 9.x versions for Windows, Macintosh and Linux
  • Adobe Acrobat XI (11.0.01 and earlier) for Windows and Macintosh
  • Adobe Acrobat X (10.1.5 and earlier) for Windows and Macintosh
  • Adobe Acrobat 9.5.3 and earlier 9.x versions for Windows and Macintosh
').'")."n[/list]"'

Security Advisory for Adobe Reader and Acrobat [Adobe]

Even though the article says the fix applies to Acrobat Reader X, it does not. The "Protected View" using the path described is not at that location. I don't know where it is in Acrobat Reader X. On Adobe's website the mitigations as described above are for Reader XI.

QuoteYaw Asare Aboagye;73084 wrote: Even though the article says the fix applies to Acrobat Reader X, it does not. The "Protected View" using the path described is not at that location. I don't know where it is in Acrobat Reader X. On Adobe's website the mitigations as described above are for Reader XI.

Meda ase @Yaw Asare Aboagye.

In that case, for those still using Adobe Reader, it makes sense to uninstall the current version & install the newest version first:    Adobe - Downloads

Adobe readies emergency patches for Reader, Acrobat | PCWorld
                       By Jeremy Kirk, IDG News Service
         
'"
    n".self::process_list_items("'.str_replace('
    ', '', '
  • Feb 18, 2013 8:15 AM  
').'")."n[/list]"'

Adobe Systems said it will release patches for two critical  vulnerabilities disclosed last week that are actively being used by  attackers.

  The company said on Saturday the patches will be released sometime this  week. Both vulnerabilities can be exploited if a user can be tricked  into opening a malicious PDF, which is usually sent to targeted victims  by email.

  The latest vulnerabilities were discovered by security vendor FireEye, which said it supplied its findings to Adobe. An analysis by Kaspersky Lab  of the exploit using the vulnerabilities found that it bypasses the  "sandbox" built into Adobe Reader, which is a technology designed to  contain attempts to install malicious software.

  Kaspersky said the exploit had a level of sophistication seen in  cyberespionage campaigns. The malicious software delivered to infected  computers can record keystrokes as well as steal passwords and  information about a computer's configuration.

 Accelerated updated

  Adobe normally issues monthly patches on the second Tuesday of the month, the same day as Microsoft,  in order to make it easier for system administrators to update systems.  But the company will release emergency fixes out of its normal schedule  for vulnerabilities that are deemed to pose a significant threat to  users.

  The vulnerabilities, CVE-2013-0640 and CVE-2013-0641, affect Adobe  Reader and Acrobat versions 9 through 9.5.3, 10 through 10.1.5 and 11  through 11.0.1, according to Adobe. Microsoft's and Apple's platforms  are affected. Patches will also be issued for Adobe Reader version 9 and  earlier for Linux.

  Last week, Adobe released security updates  for its Flash and Shockwave software that fixed a total of 19  vulnerabilities. Earlier in the month, Adobe released an emergency  update for Flash Player to quash two vulnerabilities that were being  actively exploited.

  Adobe's products are installed on millions of computers, which makes the company's software a favored choice for hackers.