Adobe launches Reader X

Adobe launches Reader X

By Robert Westervelt, News Director, SearchSecurity.com | Nov 29, 2010

Adobe Systems Inc. has released Reader X, a version of its PDF viewing software that has a new architecture designed to make it more difficult for attackers to exploit vulnerabilities and gain access to a victim's machine.

Adobe announced in July that its engineers were working on a version of Reader that was protected using a "sandboxed" mode on Windows. The technology, which is used by Google in its Chrome Web browser only enables processes to run within the confined environment of the application. It blocks actions that could be malicious, such as modifying system information.

Adobe has been struggling to keep up with the pace of zero-day vulnerabilities being targeted by attackers in its popular Reader and Acrobat PDF viewing software. Brad Arkin, senior director of product security and privacy at Adobe, said the new sandboxing technology won't stop all attacks, but it does provide an additional layer of defense.

In an interview with SearchSecurity.com in July (see video below), Arkin said the first release of Adobe Reader X would be write-only, running Reader in a low-rights process. "If an attacker found a vulnerability that today might allow him or her to take over a computer, in the future he or she would be stuck in the sandbox," Arkin said.

Arkin said the sandboxing technology is based on Microsoft's Practical Windows Sandboxing technique. If Adobe Reader attempts to write to the user's temporary folder or launch an attachment inside a PDF file using an external application, the requests are funneled through a "broker process" which allows or prevents potentially dangerous functionality, Arkin said.

"Even if exploitable security vulnerabilities are found by an attacker, Adobe Reader Protected Mode will help prevent the attacker from writing files or installing malware on potential victims' computers," Arkin wrote in the Adobe Secure Software Engineering Team blog.

Adobe also released a version of Reader X via the Android Market for devices running Google's Android OS.

This article originally appeared on SearchSecurity.com

Add comment

Post a Comment

The content of this field is kept private and will not be shown publicly.
Verification Code
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
 

knowledge_central_tab

 
 
Knowledge Central
Trusted Mobility Index
The mobile ecosystem of devices, services and networks is at a critical inflection point.While the mobile revolution is unleashing massive opportunities in both emerging and mature economies, it is also increasing in complexity and confusion. The reality is the lightning-fast adoption of powerful, smart devices is outpacing society’s ability to secure them. Today, trust in mobility hangs in the balance.
The state of the Internet, Q4, 2011
Geography appears to play a role in frequency of observed attacks on specific ports. For example, Port 23 (Telnet) is a favorite target for attacks observed to be originating from South Korea and Turkey, where it accounted for more than five times the number of attacks targeting the next most popular port (445 in both countries). Other instances of geography-based port targeting include observed attacks centered on Port 1433 (Microsoft SQL Server) in China and on Port 80 (WWW/HTTP) in Indonesia.
 
 
 
HID Global deploys a centralized, web-based IP access control solution at Fuxi Power Plant
Unable to meet the needs for real-time monitoring with its traditional patrol system, China's Fuxi Power Plant has deployed HID Global's VertX V2000.
StubHub: How to spot fraud before it happens
Whenever a list of log-on credentials is dumped onto the Web, retailers get hit with waves of automated attacks. Here's how ticket marketplace StubHub fights the threat.