Adobe mimics Microsoft, issues mega patch update

Fixes Reader zero-day flaw to stymie ongoing PDF attacks, trots out 29 patches

Adobe issued a security update today that patched 29 vulnerabilities in its popular PDF viewing and editing applications, most of them bugs that attackers can use to grab control of personal computers.

The update, Adobe's second since it announced that it would patch Adobe Reader and Adobe Acrobat quarterly -- and on the same day that Microsoft delivers its monthly security updates -- fixed one flaw that hackers have already been using in the wild.

"These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system," Adobe acknowledged in the advisory that accompanied the updates to versions 9.2, 8.1.7 and 7.1.4 of both Reader and Acrobat. "Updates apply to all platforms: Windows, Macintosh and UNIX," the advisory added.

Adobe tagged 13 of the 29 bugs with the phrase "could potentially lead to arbitrary code execution," security-speak for vulnerabilities that could be exploited to hijack a system. Like Apple, but unlike Microsoft, Oracle and other large software vendors, Adobe does not apply a rating system to the flaws it fixes.

Four of the bugs may be exploitable, Adobe confirmed, saying that for the quartet, "arbitrary code execution has not been demonstrated, but may be possible." Many of the rest could be used to crash Reader or Acrobat, but were not likely to lead to a compromised computer.

Last week, Adobe confirmed that one of the vulnerabilities patched today was being exploited using rigged PDF files in "limited targeted attacks," and promised then that it would fix the flaw today.

Since then, several security vendors, including Trend Micro and Sophos , reported that they had captured samples of the malformed PDFs. Trend Micro's analysis noted that the malicious PDF includes embedded JavaScript that utilizes "heap spraying" to compromise the machine, then extracts an also-embedded backdoor Trojan which is planted on the system.

The backdoor Trojan, dubbed "Protux" by Trend Micro, is no malware newcomer; it's been the payload for attacks that exploited vulnerabilities in Microsoft's Office suite.

Also in the Adobe patch mix today were fixes for the Reader plug-ins used by Mozilla's Firefox, Google's Chrome and Opera Software's Opera browsers. While the Firefox plug-in bug was considered critical, the one in the plug-in used by Chrome and Opera was less serious, although it could be used by identity thieves to hoodwink users into believing they were at a legitimate Web site when they actually had been shunted to a phony.

Adobe has struggled this year to keep up with a rising tide of Reader and Acrobat vulnerabilities. In March, the company quashed a PDF bug that attackers had been using for more than two months , patched Reader and Acrobat again in May to block another zero-day and fixed a Flash-related PDF flaw in July.

Today's update was the fourth this year that plugged a hole already being used by hackers.

Although Microsoft patched more vulnerabilities today (34) than did Adobe, at least one researcher pegged the latter as the company that needs to step up its security game. "The lower-hanging fruit isn't Microsoft, it's Adobe," said Wolfgang Kandek, chief technology officer at security vendor Qualys. "They seem to be getting a decent amount of attacks against their software."

Adobe has made moves to improve its security bottom line, the biggest being a promise in June to follow Microsoft's lead and release regular security updates for Reader and Acrobat. Originally, Adobe intended to post its second quarterly update last month, but a scramble during July to fix several flaws, including some introduced by Microsoft in a code "library" used by Adobe developers, ruined that plan. It announced more than a month ago that it would instead push the patch date into October.

Adobe Reader and Adobe Acrobat 9.2, 8.1.7 and 7.1.4 for Windows, Mac and Linux can be downloaded from Adobe's Web site using the links included in today's advisory . Alternately, users can use the programs' built-in update mechanism to grab the new versions.

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags MicrosoftsecurityadobePatch Tuesday

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Gregg Keizer

Computerworld (US)
Show Comments

Essentials

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?