Thursday, February 26, 2009

Adobe Acrobat products vulnerable to abuse

THE FOLLOWING FROM METASPLOIT:
Over the last two months, rumors of an unpatched vulnerability in the Adobe Acrobat products have been circulating. Last Thursday (the 19th), the Shadowserver folks confirmed that there is an exploit in the wild and that they had obtained a sample. A few hours later, Adobe confirmed the issue in their official advisory. McAfee, Symantec, and others have all chimed in saying that they have samples dating back as far as January and even December of last year. Symantec published a response almost a week before the Adobe advisory.

After a period of inexplicable silence on mitigations for a known code execution vulnerability in its Reader and Acrobat product lines, Adobe has finally posted public information on the problem but the company’s response does not offer a difinitive solution to the problem.

For more information on this, please refer to article entitled "Adobe swings and misses as PDF abuse worsens".

Big Hairy Dog is not aware of any of its customers being affected by this issue. however we want to make you aware of it in case you may encounter it at a future time. As always, we encourage you to call a BHD tech with any questions of any type at any time.
916-368-1070.