Slashdot Mirror


Microsoft Helps Adobe Block PDF Zero-Day Exploit

CWmike writes "Microsoft has urged Windows users to block ongoing attacks against Adobe's popular PDF viewer by deploying one of Microsoft's enterprise tools. Adobe echoed Microsoft's advice, saying the Enhanced Migration Experience Toolkit (EMET) would stymie attacks targeting Reader and Acrobat. Called 'scary' and 'clever,' the in-the-wild exploit went public last week when security researcher Mila Parkour reported it to Adobe after analyzing a rogue PDF document attached to spam. Adobe first warned users Wednesday of the threat, but at the time gave users no advice on how to protect themselves until a patch was ready. Microsoft stepped in on Friday. 'The good news is that if you have EMET enabled ... it blocks this exploit,' said Fermin Serna and Andrew Roths, two engineers with the Microsoft Security Response Center in an entry on the group's blog." A Symantec blog post suggests the people exploiting this vulnerability may be the 'Aurora' group responsible for the attacks on Google late last year.

5 of 93 comments (clear)

  1. I already fixed mine by mcgrew · · Score: 4, Insightful

    I ununstalled Adobe Reader and installed Foxit. Problem solved!

  2. Re:Its not zero day ... by mcgrew · · Score: 4, Informative

    When you're well past a week old, why the fuck do you keep calling it 0 day?

    Because it was exploitable on day zero. It's a week old zero day exploit.

  3. Adobe's perspective by alvinrod · · Score: 4, Insightful

    What does it say about your company when another company has to clean up your mess while you stand around, thumb up ass, not appearing to be doing anything meaningful?

    This has nothing to do about MS being good or evil. They've got a solution to the problem and it's much welcomed. Hopefully Adobe gets this fixed shortly so that people who can't make use of Microsoft's solution don't have to worry about the vulnerability either.

  4. Re:What does it say about your company... by just_another_sean · · Score: 4, Insightful

    This is /. Anything related to computer security is news. Especially when it effectivaly targets most, if not, all the users/customers we have to help all day (and night, and weekends!).

    Not every story about Microsoft is posted just because it's about Microsoft.

    --
    Creationist Textbook Stickers Declared Unconstitutional by CowboyNeal
  5. ASLR by js3 · · Score: 4, Informative

    According to the article..

      "Normally Address Space Layout Randomization (ASLR) would help prevent successful exploitation. However, this product ships with a DLL (icucnv36.dll) that doesn’t have ASLR turned on."

    So enable ASLR on the effing DLL and release a patch, problem solved? Nothing would make me work overtime and on the weekend than a highly visible level 1 bug. Adobe developers must have it good!

    --
    did you forget to take your meds?