Adobe investigating reports of new critical bug in Reader, Acrobat

Advertisement
By Reuters | Updated: 14 February 2013 15:52 IST
Adobe Systems Inc is investigating a report by a cyber-security firm that hackers exploited previously unknown bugs in its Reader and Acrobat software to launch sophisticated attacks on personal computers.

FireEye, a Silicon Valley company that helps businesses fight cyber-attacks, told Reuters it obtained so-called PDF files tainted with malicious software, which can take advantage of the newly discovered bugs.

It declined to identify any victims of the attacks.

Advertisement

A spokeswoman for Adobe said that the company is investigating the report, which surfaced late on Tuesday. She declined to elaborate.

This has been a busy year so far for Adobe's security team. In January, the company pushed out security updates to fix vulnerabilities in Reader, Acrobat and Flash, as well as a program known as ColdFusion that is used to build websites.

Advertisement

Last week, it rushed out a fix for Flash Player after security software maker Kaspersky Lab identified a critical bug that enabled hackers to install "back doors" and take control of PCs running on Microsoft Corp's Windows operating system or Apple Inc's Mac OS X.

Adobe's software has long been a popular target for hackers, who attack PCs by finding bugs in widely used programs that they can then exploit to insert viruses on computers. Experts estimate that Reader and Acrobat programs for accessing PDF documents and Flash Player for accessing Internet content are installed on more than 1 billion PCs.

Advertisement

Hackers exploiting the most recently discovered vulnerability use PDF files to infect PCs, according to FireEye.

When the victim opens the PDF, a visa application form appears onscreen, and a virus installs a covert communications channel with a remote computer known as a "command and control" server, which hackers use to control infected PCs, said Zheng Bu, senior director of research at FireEye.

Advertisement

He said the virus also installs a third malicious file on the infected computer, but declined to elaborate.

Adobe has yet to provide advice on how to protect PCs against attack. FireEye said computer users should avoid opening unfamiliar PDFs, especially when coming from unknown sources.

FireEye said on its blog it has observed attacks on PCs running Adobe Reader 11, the most-recent version of the software, as well as Reader 9 and Reader 10.

Adobe said on its own security blog that the issue also affected Acrobat XI, the current version of the software used to create PDF documents.

© Thomson Reuters 2013

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases of the Week (Mar 30th - Apr 5th): From Aamir Khan's Sitaare Zameen Par
  2. PS Plus Monthly Games for April Revealed
  3. Vivo V70 FE Launched in India With 7,000mAh Battery, 200-Megapixel Main Camera
  4. Best Mobiles Under Rs. 30,000 in India
  5. Realme 16 5G Launched in India With Selfie Mirror Feature: Check Price
  6. Google AI Pro Subscribers Now Get 5TB of Storage Across Drive, Photos
  7. Axis Bank Adds Aadhaar Face Authentication: How to Update Mobile Number
  8. Oppo F33, Oppo F31 Pro Launch Timeline, Price Range Leaked
  9. OnePlus 15R Price in India Hiked Amidst Soaring Cost of Memory Components
  1. Oppo F33, Oppo F31 Pro Launch Timeline, Price Range Revealed in New Leak
  2. Capcom Adds Original Versions of Resident Evil 1, 2 and Resident Evil 3 Nemesis to Steam
  3. Google's Next Fitbit Wearable Could Launch Without a Display; Said to Require Paid Subscription
  4. CFTC-FTX Settlement: Former FTX Executive Nishad Singh to Pay $3.7 Million, Faces Trading Ban
  5. Slack Upgrades Slackbot With New AI Features to Turn It Into an Enterprise Agent
  6. Australia Mandates Financial Services Licences for Crypto Exchanges Under New Bill
  7. DoT Reportedly Extends SIM Binding Mandate Till the End of 2026
  8. Government Migrates 16.68 Lakh Official Email Accounts to Zoho Cloud, Spends Rs. 180 Crore
  9. Infinix Note 60 Pro India Launch Date Revealed; Company Teases Active Matrix Feature on Rear Panel
  10. Naughty Dog's Neil Druckmann Mentions 'Road Ahead' for the Last of Us, Teasing the Last of Us Part 3
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.