Verizon Fios Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 20 February 2013

Security News: Adobe Reader/Acrobat 0-Day with Sandbox Bypass

Posted on 17:05 by Unknown
Some of you have undoubtedly heard the big news in the exploit world this week. There is a new Adobe Reader/Acrobat exploit in the wild that bypasses ASLR (Address Space Layout Randomization), DEP (Data Execution Prevention), and, most importantly, the sandbox ("Protected Mode") that was introduced in Adobe Reader X. Adobe confirmed the critical-rated vulnerabilities as CVE-2013-0640, and CVE-2013-0641 on Wednesday night, February 13, 2013.  The vulnerability applies to versions 11.0.01 and earlier (XI), 10.1.5 and earlier (X), and 9.5.3 (9) and earlier. There is no fix available as of the time of this writing.

The exploit does not defeat "Protected View" that was introduced in Adobe Reader XI. However, it does not need to because Protected View is disabled by default. It is highly recommended to all Adobe users to enable Protected View as described in the Adobe link below. The exploit uses ROP (Return Oriented Programming) as one would expect to get around the standard defenses, and employs several anti-analysis mechanisms such as TLS (Thread Local Storage) callbacks and fake Export Table entries.

This news is particularly important because there have been no confirmed Adobe sandbox bypasses ever published, until now. Some readers may note that "Group IB" (a group based out of Russia) claimed to have a sandbox escape in November, 2012 when they posted a tantalizing video of Adobe Reader XI being exploited http://www.youtube.com/watch?v=uGF8VDBkK0M.  However, that particular end-to-end exploit is seeming more like vaporware every month that passes without independent confirmation.

Adobe CVE Report:
https://www.adobe.com/support/security/advisories/apsa13-02.html

FireEye has published a partial technical description of some of the shellcode from the in-the-wild exploit.  FireEye has withheld full details for now at Adobe's request.
http://blog.fireeye.com/research/2013/02/the-number-of-the-beast.html

UPDATE: Adobe has released a patch for CVE-2013-0640 and CVE-2013-0641 as of Wednesday, February 20, 2013.  You can find the security bulletin here: http://www.adobe.com/support/security/bulletins/apsb13-07.html
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • How to compile busybox with Android NDK for both ARM and x86 architectures
    I was looking for a way to run busybox on a Motorola RAZRi with an x86 Intel Atom processor but I couldn't find any Android app from th...
  • Security and Trust when Everything has a Computer In It
    Security and Trust when Everything has a Computer In It Recently, Panic Software announced that they had opened up an HDMI display adapter ...
  • Sony Cyber-shot DSC-HX200V 18.2 MP 30 x High Zoom GPS Digital Camera - BLACK
    Sony Cyber-shot DSC-HX200V 18.2 MP 30 x High Zoom GPS Digital Camera - BLACK Blogger Opportunity Giveaway from June 17 to  July 12 Come and ...
  • Free Blogger Opp – Timjan Design Malachite 5/1
    Here comes another Visionary Bri blogger opportunity. Sign up now for the Timjan Bloomers Giveaway. Our sponsor, Timjan Design , has offered...
  • Hackers that solve problems...
    The nation and the world at large are struggling to come to grips with the fact that we are now more than ever vulnerable in our daily lives...
  • How to build Python-4-Android for the ARM Neon
    Currently the Py4A project does not compile for the ARM Neon architecture. If you try to run ndk-build on the project by setting the APP_A...
  • How to Cross-Compile libiconv for Android
    If your legacy C/C++ code includes <iconv.h> to convert the encoding of characters from one coded character set to another, and you ne...
  • How to compile libogg for Android
    To compile libogg for Android, you just need to create an appropriate jni/Android.mk makefile with the minimum set of files and options need...
  • Problems with new version of rpmbuild
    The Problem With the new version of rpmbuild installed on CentOS 6.x, if you try to use an old RPM spec file, you will get an error like the...
  • Sony Cyber-shot DSC-HX200V Giveaway
    Hosted by: NYSavingSpecials and Your Fashion Resource ,  Co-hosted by Melissa Say What? ,  Barbara's Beat ,  LibbysLibrary ,  Confessio...

Categories

  • amazon
  • amazon.com
  • Android
  • Apple
  • Arduino
  • ARM
  • baby
  • baby reviews
  • back to school
  • beef jerky
  • bicycle. wagon
  • bike
  • Blanket Buddies
  • blogging
  • Blogging with The Tate's
  • books
  • busybox
  • camera
  • camera giveaway
  • candle giveaway
  • candles
  • CaseApp
  • CentOS
  • coffee
  • david haskell
  • dermorganic
  • DHCP
  • digital camera
  • events
  • Florida
  • Fortran
  • free blogger giveaway
  • free blogger sign-ups
  • full of flavor
  • giveaways
  • GNU
  • GPON
  • hair care
  • happy husband
  • Hot tea
  • Husband and Wife perspective
  • iMac
  • ipad
  • iphone
  • iphone case
  • iphone case review
  • Javascript
  • Keurig Coffee Review
  • Keurig Review
  • Kindle
  • ksh
  • LifeProof iPhone Case Review
  • Linux
  • MacOSX
  • Malachite Bloomers
  • man and women perspective
  • meat
  • Mips
  • Network
  • Pretzel Crisps
  • Pretzels
  • product reviews
  • products
  • Python
  • Router
  • scentsy
  • scentsy candles
  • school
  • scooter
  • security system
  • skin care
  • snacks
  • sony
  • sony cyber-shot
  • Stuff Animal
  • suface pro
  • Summer
  • summer fun
  • surface pro giveaway
  • techno thriller
  • Timjan Design
  • too much information
  • UNIX
  • vegan
  • vegan products
  • verizon
  • verizon fios
  • VitaminsBaby
  • waterproof case
  • Windows
  • x86
  • yummy

Blog Archive

  • ▼  2013 (41)
    • ►  November (2)
    • ►  October (2)
    • ►  September (3)
    • ►  August (3)
    • ►  July (2)
    • ►  June (2)
    • ►  May (6)
    • ►  April (8)
    • ►  March (2)
    • ▼  February (5)
      • How to compile busybox with Android NDK for both A...
      • Security News: Adobe Reader/Acrobat 0-Day with San...
      • Verizon Fios Home Monitoring Review
      • How to build the gcc Fortran cross-compiler for An...
      • How to root Motorola RAZRi XT890 running Android 4...
    • ►  January (6)
  • ►  2012 (17)
    • ►  December (3)
    • ►  November (4)
    • ►  October (8)
    • ►  July (1)
    • ►  June (1)
Powered by Blogger.

About Me

Unknown
View my complete profile