Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Adobe to release emergency patches for Reader, Acrobat

The vulnerabilties could allow an attacker to steal passwords, record keystrokes and other information

Adobe Systems said it will release patches for two critical vulnerabilities disclosed last week that are actively being used by attackers.

The company said on Saturday the patches will be released sometime this week. Both vulnerabilities can be exploited if a user can be tricked into opening a malicious PDF, which is usually sent to targeted victims by email.

The latest vulnerabilities were discovered by security vendor FireEye, which said it supplied its findings to Adobe. An analysis by Kaspersky Lab of the exploit using the vulnerabilities found that it bypasses the "sandbox" built into Adobe Reader, which is a technology designed to contain attempts to install malicious software.

Kaspersky said the exploit had a level of sophistication seen in cyberespionage campaigns. The malicious software delivered to infected computers can record keystrokes as well as steal passwords and information about a computer's configuration.

Adobe normally issues monthly patches on the second Tuesday of the month, the same day as Microsoft, in order to make it easier for system administrators to update systems. But the company will release emergency fixes out of its normal schedule for vulnerabilities that are deemed to pose a significant threat to users.

The vulnerabilities, CVE-2013-0640 and CVE-2013-0641, affect Adobe Reader and Acrobat versions 9 through 9.5.3, 10 through 10.1.5 and 11 through 11.0.1, according to Adobe. Microsoft's and Apple's platforms are affected. Patches will also be issued for Adobe Reader version 9 and earlier for Linux.

Last week, Adobe released security updates for its Flash and Shockwave software that fixed a total of 19 vulnerabilities. Earlier in the month, Adobe released an emergency update for Flash Player to quash two vulnerabilities that were being actively exploited.

Adobe's products are installed on millions of computers, which makes the company's software a favored choice for hackers.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Adobe, Adobe Systems, Apple, FireEye, Kaspersky, Kaspersky Lab, Linux, Microsoft
Comments are now closed.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: Adobe Systems, security, Desktop security, data breach, data protection, Exploits / vulnerabilities, malware
Latest Blog Posts
Whitepapers
  • Stop Paying the Earth for Global Roaming
    Why do we continue to pay the earth for global roaming? With Telstra increasing global roaming charges by 100-500% in over 180 countries, bill shock can only get worse. This paper investigates why, what and how your company can address the need for global coverage.
    Learn more »
  • How to Successfully Select an ERP System
    An Enterprise Resource Planning (ERP) system is a series of software applications that collect and compiles data from different departments to enhance collaboration and co-ordination within the business. If you’re looking to implement your first ERP system, or to upgrade from an existing system, this whitepaper offers eight simple steps for selection that will lead to long-term strategic success.
    Learn more »
  • Rebranded Quadmark revamps its IT solutions with Google Apps
    The Singapore office was using Exchange as its email server but encountered various issues such as storage capacity limitations and difficulty in managing spam. Adding new users to the server was also a hassle that often required a third party vendor, resulting in a waste of time and resources. Quadmark also experienced email performance issues that slowed down their employees’ response time, leading to frustration among staff and clients. Quadmark’s management felt that it was unacceptable to continue it’s current solution and thus decided to streamline its IT infrastructure alongside its rebranding plans. The business wanted a unified and consolidated email service for its various offices. Quadmark also wanted to be able to house files and documents on the cloud.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Latest Jobs
Salary Calculator

Supplied by

View the full Peoplebank ICT Salary & Employment Index

Recent comments

Computerworld
ARN
Techworld
CMO