Adobe Reader and Acrobat Remote Code Execution Vulnerability
December 17, 2009 by admin · Leave a Comment
Adobe has released a security advisory to address a vulnerability in Adobe Reader and Acrobat. By convincing a user to open a specially crafted PDF file, an attacker may be able to execute arbitrary code. Public reports currently indicate active exploitation of this vulnerability.
US-CERT encourages users and administrators to do the following to help mitigate the risks until the vendor is able to provide an update:
- * Review Adobe security advisory APSA09-07 and apply any necessary solutions listed in the document.
- * Use caution when opening PDF files from untrusted sources.
- * Disable JavaScript in Adobe Acrobat and Reader. To do this, click “Edit,” then “Preferences” and then “JavaScript,” and uncheck “Enable Acrobat JavaScript.”
