Adobe to release emergency patches for Reader, Acrobat
- 17 February, 2013 23:47
Adobe Systems said it will release patches for two critical vulnerabilities disclosed last week that are actively being used by attackers.
The company said on Saturday the patches will be released sometime this week. Both vulnerabilities can be exploited if a user can be tricked into opening a malicious PDF, which is usually sent to targeted victims by email.
The latest vulnerabilities were discovered by security vendor FireEye, which said it supplied its findings to Adobe. An analysis by Kaspersky Lab of the exploit using the vulnerabilities found that it bypasses the "sandbox" built into Adobe Reader, which is a technology designed to contain attempts to install malicious software.
Kaspersky said the exploit had a level of sophistication seen in cyberespionage campaigns. The malicious software delivered to infected computers can record keystrokes as well as steal passwords and information about a computer's configuration.
Adobe normally issues monthly patches on the second Tuesday of the month, the same day as Microsoft, in order to make it easier for system administrators to update systems. But the company will release emergency fixes out of its normal schedule for vulnerabilities that are deemed to pose a significant threat to users.
The vulnerabilities, CVE-2013-0640 and CVE-2013-0641, affect Adobe Reader and Acrobat versions 9 through 9.5.3, 10 through 10.1.5 and 11 through 11.0.1, according to Adobe. Microsoft's and Apple's platforms are affected. Patches will also be issued for Adobe Reader version 9 and earlier for Linux.
Last week, Adobe released security updates for its Flash and Shockwave software that fixed a total of 19 vulnerabilities. Earlier in the month, Adobe released an emergency update for Flash Player to quash two vulnerabilities that were being actively exploited.
Adobe's products are installed on millions of computers, which makes the company's software a favored choice for hackers.
Send news tips and comments to firstname.lastname@example.org. Follow me on Twitter: @jeremy_kirk
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
Trust issue looms large for tech companies capitalizing on personal data
5 women who've made it in IT
Five trends affecting legal CIOs
CIO Roundtable: The changing face of security
Bitcoin malware count soars as cryptocurrency value climbs
Assessing IP Telephony Total Cost of Ownership
Understanding total cost of ownership (TCO) of IP telephony (IPT) and unified communications (UC) implementations is critical to sound decision making. Based on data gathered from 211 Enterprises, this whitepaper reveals TCO for each vendor across a range of implementation sizes.
Keeping up with an Increasingly Sophisticated Threat Environment
Relying on traditional signature based Anti Virus alone is simply not sufficient to prevent today’s onslaught of new, sophisticated and advanced malware. This whitepaper describes in detail, some trends and statistics on the malware detection, it then introduces a multi-vector approach to accurately detect malware in the IT environment, and verify that existing anti malware already deployed are functioning optimally.
Reducing Telephony Costs in Healthcare
Learn how a not-for-profit national New Zealand health service employed a Unified Communication (UC) solution to achieve the more responsive, flexible telephony that’s critical for patients and nursing, along with greater visibility, and at least 30% annual savings.