This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Adobe Reader exploit in the wild

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.html?storyid=3958
Last Updated: 2008-02-09 02:38:22 UTC - "The Adobe Reader vulnerability… is being exploited in the wild! A malicious PDF file (called 1.pdf in this example) served from IP address "85.17.221.2" (not active at this time) contains a malware specimen called Trojan, a variant of Zonebac. The IP address belongs to LeaseWeb, a hosting provider in The Netherlands we already notified…"

- http://secunia.com/advisories/28802/
Software: Adobe Reader 8.x …
Solution: Update to version 8.1.2 …
Original Advisory: Adobe Reader 8.1.2 Release Notes:
http://www.adobe.com/go/kb403079

:ph34r:
Updated…

- http://isc.sans.org/diary.html?storyid=3958
Last Updated: 2008-02-09 03:12:27 UTC …(Version: 2) - "UPDATE 1
VeriSign - iDefense sent us some additional information. Here is what they told us:
> VeriSign - iDefense is observing exploitation of a recently patched vulnerability in Adobe Acrobat Reader. This vulnerability was discovered by Greg McManus of iDefense Labs and reported to Adobe in October 2007.
> Since January 20, 2008 banner ads are actively serving malicious PDF files that exploit the vulnerability and install the Zonebac Trojan. Once installed the Trojan kills various anti-virus products and modifies search results and banner ads.
> Until 2 days ago, this attack did not have a patch available while being actively exploited in the wild. A similar attack occurred in October 2007 when the same group used a Realplayer 0-day exploit to install the Zonebac Trojan.
> No anti-virus vendors currently detect the malicious PDF files though we have provided samples to all. This type of exploit works for both web browser and email attack vectors. Exploitation affects all 7.x versions of Adobe Acrobat Reader and versions prior to 8.1.2. Complete mitigation requires upgrading to Adobe Acrobat 8.1.2.
> Vulnerability Timeline:
* Adobe Reader Buffer Overflow Vulnerability (iDefense orig.) (ID#464641, Oct. 10, 2007)
* Virus Report (http://www.pcprimipassi.it/servizifree/forum/forum_posts.asp?TID=10066, Jan. 20, 2008)
* Adobe Acrobat 8.1 Undisclosed Buffer Overflow Vulnerability (ID#467355, Feb. 6, 2008)
* Immunity POC Exploit (http://www.immunityinc.com/partners-index.shtml, Feb. 6, 2008)
* Adobe Reader Vulnerability Exploitation in the Wild (ID#467384, Feb. 8, 2008)
* Adobe Security Advisory APSA08-01 ( http://www.adobe.com/support/security/advi…/apsa08-01.html , Feb. 7, 2008)
* iDefense Receives Hostile PDF Sample (Feb. 7, 2008)
* iDefense Customer Notification (ID#467398, Feb. 8, 2008)
> Additional details:
1c130a41aa6866bc081cf096bbd08da3 1.pdf
68b804a8463c9261b991f1c92e05f801 b.pdf …
We ran "1.pdf" through VirusTotal and got these results (0/32). Pretty scary!"

:ph34r:
FYI…

Neosploit Updated to Include an Acrobat Exploit
- http://preview.tinyurl.com/6mlnq6
05-05-2008 (Symantec Security Response Blog) - "On about April 18th, Symantec's DeepSight honeypots began capturing a new iteration of the Neosploit exploit toolkit. It appears that the pervasive exploit kit has been updated to take advantage of a circa February 2008 vulnerability in Adobe Acrobat Professional and Reader. What makes this attack vector of particular concern is that it will work reasonably silently through most browsers. If a user is enticed to a hostile Web site (who knows which ones are hostile these days) using the browser of their choice, it is reasonably likely that their computer will become infected provided that they have Acrobat installed on their computer. Although the vulnerability has been patched since early February, I suspect that many users have not applied this patch yet. We highly recommend that if you haven’t done so, go and get the latest patched versions of Adobe Acrobat Reader and Professional from here: http://www.adobe.com/support/security/advi…/apsa08-01.html …"

- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2042
Last revised: 5/8/2008

Security Updates available for Adobe Reader and Acrobat 7 and 8
- http://forums.whatthetech.com/Adobe_Reader…sed_t91670.html

:ph34r: