Thursday

0day: PDF exploiting windows

Well, after 0-day exploit: Quicktime owns Firefox and after 0 day: Exploiting by using Windows Media Files , pdp from Gnucitizen is closing the season with a zeroday adobe pdf exploit. Details are not disclosed until Adobe releases a patch. But seen his track record, we can better believe him.


Adobe Acrobat/Reader PDF documents can be used to compromise your Windows box. Completely!!! Invisibly and unwillingly!!! All it takes is to open a PDF document or stumble across a page which embeds one.

My advise for you is not to open any PDF files (locally or remotely). Other PDF viewers might be vulnerable too. The issues was verified on Windows XP SP2 with the latest Adobe Reader 8.1, although previous versions are also affected.

UPDATE (22/09/2007): You can watch this the Proof of Concept on this Youtube movie.

0 comments: