Patch Adobe Reader now or risk a major security attack

data privacy
(Image credit: Shutterstock / Zeeker2526)

Adobe has published a security update for a handful of its products after discovering serious vulnerabilities apparently being exploited in the wild.

Issuing a security bulletin, Adobe said the patch is designed for Acrobat DC, Acrobat Reader DC, Acrobat 2020, Acrobat Reader 2020, Acrobat 2017, and Acrobat Reader 2017, both on Windows and Mac OS, ZDNet reported.

Adobe described the patched flaws, labeled as CVE-2021-28550, as “critical” and “important”, saying they were being exploited in the wild, and, if successfully exploited, could lead to arbitrary code execution. It basically means the attacker could use the productivity programs to run various types of malicious code on the target machine.

Discussing the threat with ZDNet, senior cyber threat intel analyst at Digital Shadows, Sean Nikkel, said nation-states frequently use malicious PDF files in their cybercriminal activities mostly due to the ubiquity of Adobe products, both in private and public sectors.

Describing the Adobe suite as the “Microsoft of a lot of office productivity software”, he said that criminals often hide malware in fake financial documents, shipping labels or news articles, which often come in the PDF format.

Remote working as a liability

Nikkel also said that criminals don’t shy away from creating a malicious website where they could host weaponized PDF files.

"Generally, PDF documents, which frequently are opened either via browser or a reader such as Adobe Acrobat or Reader, can contain malicious Javascript or allow some other system interaction that allows code execution or other vectors of attack to occur, sometimes without the user knowing,” he explained. 

Nikkel believes that the major increase in attacks, that’s been spotted recently, can be attributed to remote working. With many employees accessing corporate networks via home devices, cybercriminals have been hard at work at trying to exploit them.

In many cases, they succeed, due to the fact that remote workers are no longer under the protection of their corporate IT network and security experts.

Via: ZDNet

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Cyber-security
Adobe releases software updates to patch security issues
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
Representational image of a cybercriminal
Microsoft just patched a host of worrying security issues, so update now
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
Outlook
Dangerous Microsoft Outlook flaw could let hackers send out malware via email
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
Latest in Software & Services
TinEye website
I like this reverse image search service the most
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Autonomous finance
Quickbooks vs Quicken: what are the main strengths and weaknesses for your business
finance
Quickbooks vs Xero: which is the best for your business?
Latest in News
The Samsung Galaxy S21 series of phones lying face down.
Samsung announces One UI 7 is coming to older phones after all, but the launch is still a mess
Using Zipped files and folders in Windows 11
Windows 11 should soon be faster at extracting files from compressed ZIPs – and it’s about time, frankly
The player prepares for a fight in Metal Eden.
I loved the bits of Metal Eden that I played and soon you'll be able to try it too thanks to this upcoming free demo
Apple iPhone 16 Pro HANDS ON
The iPhone 18 might get a major chip upgrade after all
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Oppo Watch Mini X2 teaser
Oppo Watch X2 Mini teaser could be our first glimpse of the smaller OnePlus Watch 3