Sign in
Microsoft Malware Protection Center
Threat Research & Response Blog
Options
Blog Home
About
Send to friend
RSS for Posts
Atom
Search Blogs
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Search
Tags
.lnk exploits
bing
Chymine
conference
conficker
CVE-2010-2568
guidance
KB2286198
MSRT
Pages
passwords
piracy
research
rogue
search
SEO
SIR
smartscreen
spam
Stuxnet
telemetry
Vobfus
Partner Links
Windows Live OneCare safety scanner
A free service designed to help ensure the health of your PC.
Microsoft Security Response Center
The Microsoft Security Response Center (MSRC) identifies, monitors, resolves, and responds to Microsoft software security vulnerabilities.
Microsoft Security Essentials
Get high-quality, hassle-free antivirus protection for your home PC now.
Microsoft Forefront
Microsoft Forefront: a comprehensive security product portfolio.
Windows Defender
Windows Defender Homepage
Microsoft AntiSpam
Microsoft AntiSpam
Industry Links
ICSA Labs
Virus Bulletin
Virus Bulletin: Independent Malware Advice
West Coast Labs
West Coast Labs (WCL) is one of the world's leading independent test facilities.
AV-Test
AV-Test.org - Tests of Anti-Virus and Security-Software
AV-Comparatives
Independent comparatives of Anti-Virus Software
Partner Blogroll
Forefront Client Security Team Blog
The scoop from the FCS engineering team.
Forefront Team Blog
Information about what's happening with the entire Microsoft Forefront Family of products.
Michael Howard's Web Log
A Simple Software Security Guy at Microsoft!
Microsoft Security Research & Defense Blog
Information from Microsoft about vulnerabilities, mitigations and workarounds, active attacks, and other related guidance.
The Microsoft Security Response Center Blog
Working to help protect customers from vulnerabilities in Microsoft software.
GCR Security Blogs
MMPC Links
Microsoft Malware Protection Center
The Microsoft Malware Protection Center (MMPC) Portal.
Microsoft Security Intelligence Report
Microsoft Security Intelligence Report
Archive
Archives
September 2010
(1)
August 2010
(8)
July 2010
(7)
June 2010
(6)
May 2010
(5)
April 2010
(5)
March 2010
(9)
February 2010
(7)
January 2010
(3)
December 2009
(4)
November 2009
(9)
October 2009
(6)
September 2009
(8)
August 2009
(4)
July 2009
(5)
June 2009
(7)
May 2009
(8)
April 2009
(18)
March 2009
(10)
February 2009
(8)
January 2009
(5)
December 2008
(11)
November 2008
(7)
October 2008
(12)
September 2008
(8)
August 2008
(11)
July 2008
(4)
June 2008
(3)
CVE-2010-0188: Patched Adobe Reader Vulnerability is Actively Exploited in the Wild
TechNet Blogs
>
Microsoft Malware Protection Center
>
CVE-2010-0188: Patched Adobe Reader Vulnerability is Actively Exploited in the Wild
CVE-2010-0188: Patched Adobe Reader Vulnerability is Actively Exploited in the Wild
mmpc
8 Mar 2010 10:30 PM
Comments
0
While recently analyzing a malicious PDF file, I noticed a vulnerability exploited by the sample which I've never encountered before. After a bit of research I came to the conclusion that this specific sample exploited
CVE-2010-0188
. This is a fresh vulnerability, information about which was just published this February. It is described as possibly leading to arbitrary code execution, which is exactly what’s happening.
When the PDF file is loaded, Adobe Reader opens and then closes, while an executable file named a.exe is dropped directly onto the
C:\
drive. The dropped executable, which is actually embedded into the PDF file, tries to connect to a
.biz
registered domain to download other files. JavaScript is again used to successfully exploit this vulnerability, so disabling it for unknown documents might be a good idea.
We currently detect the malicious file as
Exploit:Win32/Pidief.AX
(SHA1: 908ae499a474e3006253417c658e055a633e75a1) and the dropped malware as
TrojanDownloader:Win32/Qaantiz.A
.
Fortunately Adobe has released an update to address the vulnerability which is offered automatically to all users. Read Adobe's security bulletin
here
and upgrade to the latest version of Adobe Reader and Acrobat. Users can pull down the 'help' menu and click on 'check for updates' to ensure that they're running the latest version.
As good practice, we advise every user to always update their programs as well as their operating system. We also advise users not to open files whose origins they don't trust.
Marian Radu
MMPC Dublin
Comments