Adobe PDF Reader and Acrobat Zero-Day Exploit 9.2

From ATTWiki
Jump to: navigation, search

Adobeacrobatlogo.jpg
This is an exploit that affects Adobe PDF Reader and Acrobat. It is very serious and has not been addressed by Adobe.

This is how Adobe's site explains the problem:

Adobe has confirmed a critical vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions that could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild. Adobe recommends customers follow the mitigation guidance below until a patch is available.

How to close this vulnerability:

  1. Launch Acrobat or Adobe Reader.
  2. Select Edit>Preferences
  3. Select the JavaScript Category
  4. Uncheck the 'Enable Acrobat JavaScript' option
  5. Click OK


Adobe will not release a fix until January 12, 2010.

You can read more here:


Note about Zero-day attack: "A zero-day (or zero-hour) attack or threat is a computer threat that tries to exploit computer application vulnerabilities that are unknown to others, undisclosed to the software vendor, or for which no security fix is available."