U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog|430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link|Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic|Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges|Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed|Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs|CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks|RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow|GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents|XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t|U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog|Hackers Steal Data of 4.38 Million Aflac Japan Customers|U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog|430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link|Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic|Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges|Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed|Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs|CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks|RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow|GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents|XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t|U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog|Hackers Steal Data of 4.38 Million Aflac Japan Customers|
Advertisement

Ad Placeholder

Full Width × 90

Hacking

Adobe Reader vulnerability reveals where a PDF is opened

The McAfee security firm found an Adobe Reader vulnerability that reveals where a PDF document is opened. The McAfee security firm found an Adobe Reader vulnerability that reveals where a PDF document is opened, once again Adobe products are the center of attention of security experts after the numerous attacks that have exploited flaws in its products for cyber espionage campaigns. […]

Adobe Reader vulnerability reveals where a PDF is opened

The McAfee security firm found an Adobe Reader vulnerability that reveals where a PDF document is opened.

The McAfee security firm found an Adobe Reader vulnerability that reveals where a PDF document is opened, once again Adobe products are the center of attention of security experts after the numerous attacks that have exploited flaws in its products for cyber espionage campaigns.

McAfee provided only general information to the press for obvious reasons not supplying details of the Adobe Reader vulnerability that affect all Adobe Reader versions, including last one.

It must be clear that the Adobe Reader vulnerability discovered doesn’t allow remote code execution, anyway McAfee consider it a security issue and have alerted the Adobe company.

The blog post reported:

“Recently, we detected some unusual PDF samples. After some investigation, we successfully identified that the samples are exploiting an unpatched security issue in every version of Adobe Reader including the latest “sandboxed” Reader XI (11.0.2). Although the issue is not a serious problem (such as allowing code execution), it does let people track the usage of a PDF. Specifically, it allows the sender to see when and where the PDF is opened.”

The anomalous behavior is observable when the launches a link to another file path, which calls on a JavaScript API. The Adobe Reader displays a security warning to inform the user that he is going to open an external resource such as an Internet URL.

Adobe Reader vulnerability Warning

 

The Reader doesn’t provide information on the availability of the external resource, if doesn’t exist in fact the API doesn’t display any message and returns any TCP traffic.

Adobe Reader vulnerability TCP Traffic

Haifei Li, author of the post, revealed that it is possible to manipulate a parameter of the API to obtain information on the document  such as the location of a document on a system (using the JavaScript call this.path).

The information could be collected by the attacker to gather information on the target as explained in the post:

“Malicious senders could exploit this vulnerability to collect sensitive information such as IP address, Internet service provider or even the victim’s computing routine,” Li wrote. “In addition, our analysis suggests that more information could be collected by calling various PDF JavaScript APIs.”

“An APT [advanced persistent threat] attack usually consists of several sophisticated steps. The first step is often collecting information from the victim; this issue opens the door.”

McAfee suggests to the users to disable JavaScript in Reader until the patch will be released.

Pierluigi Paganini

(Security Affairs – Security)