阅读全部内容

微软安全公司警告利用PDF漏洞的攻击

  [字体: ]


Microsoft, security firms warn over PDF attacks

Online attackers began targeting a recently fixed vulnerability in Adobe Acrobat, spamming out e-mails with a malicious attachment in the Portable Document Format (PDF), security firms and Microsoft warned last week.

The e-mail attack aims to compromise systems that have not fixed a flaw in the way Adobe Acrobat handles mailto links in PDF files. The vulnerability affects a variety of versions of Adobe Acrobat and Adobe Acrobat Reader on running on Windows XP using Internet Explorer 7. Adobe fixed the security hole a week ago, and attacks started appearing the next day, according to Symantec.

In a blog entry on Thursday, Microsoft acknowledged the attack and said that, while it used Adobe's application to execute, the actual flaw is in Microsoft's software.

"Because the vulnerability mentioned in this advisory is in the Microsoft Windows ShellExecute function, these third party updates do not resolve the vulnerability – they just close an attack vector," Bill Sisk, a member of the Microsoft Security Response Center (MSRC), stated in the posting. "As part of our SSIRP process we currently have teams worldwide who are working around the clock to develop an update of appropriate quality for broad distribution."

Portable Document Format (PDF) files have increasingly been used as a means to deliver spammers' advertisements, but only rarely has the file format been used as an attack vector. In September, e-mail messages with PDF attachments only accounted for 1 percent of all spam, according to e-mail and content security firm Proofpoint. Word documents account for more than 3 percent. Spammers have even starting sending out audio advertisements attached to e-mail messages in the MP3 format.


微软安全公司警告利用PDF漏洞的攻击

安全公司和微软上周警告说,网络黑客开始以最近在adobe acrobat中确定的漏洞为目标进行攻击,发送pdf格式的恶意附件的垃圾邮件。

这个邮件攻击的目标是那些没有修复漏洞的系统,该漏洞是adobe acrobat处理pdf文件中的maitlo连接时产生的。这个漏洞影响多种版本的adobe acrobat和adoba acrobat reader,并且这些版本都运行在利用ie7的windows xp系统中。一个星期之前adobe修复了这个漏洞,并且在修复漏洞的第二天攻击就出现了,根据symantec的报告。
在星期四的一篇blog中,微软承认了这个攻击并说该攻击是利用adobe的应用来执行,真正的漏洞是微软的软件。

”因为这个声明所提及的漏洞是微软shellexecute功能,因此第三方的更新是不能解决这个漏洞--他们只是关闭了一个攻击的向量。“bill说,msrc的一位成员说“作为我们ssirp过程中的一部份,我们现在有全球的团队24小时不停的工作为广泛的分布建立一个合适的更新。”

PDF文件已被越来越多地用来作为一种手段来运送垃圾邮件广告,但只有少数的文件格式被用来作为一个攻击向量。据电子邮件和内容安全产商的证据显示,九月份包含PDF附件的邮件信息仅占所有垃圾邮件的1%,word文件占了超过3%。垃圾邮件发送者甚至已经开始发送音频广告通过在邮件的附件中附带mp3格式文件。



日期:2007年10月

【 hits:】 【 评论 】 【 推荐 】 【 打印
上一篇:六城会官方网站遇黑客 技术部击退攻击仅用90秒
下一篇:VoIP新漏洞可被实施跨站脚本攻击(XSS)
相关新闻      
为什么选择连天科技
河南连天科技有限公司 ( LianTian Technology Co.,Ltd. ),是国内从事网络安全的高科技企业之一。
连天科技是Radware、Mirage、绿盟、AVENTAIL、Sonicwall、比蒙等国际国内知名厂商的河南区域战略合作伙伴,我们本着“专业、专注、全心、全程”的服务理念为客户提供全面的信息安全解决方案,协助客户建立安全可靠的运营环境。