CIO  |  IT Security & Policy  |  LONI  |  LOUIS  |  UIS  |  UNI  |  USS  |  MDAC  |  Moodle
IT Security & Policy
Adobe Acrobat and Reader Vulnerability

We have received reports of malicious hackers exploiting a zero-day vulnerability in Adobe PDF Reader and Acrobat 9.2 and earlier.   Adobe had released very few details about the vulnerability and no mitigation guidance or patches.  All we know is that the exploit uses JavaScript embedded in the PDF document.  Please advise your users to disable JavaScript in Adobe Reader and/or Acrobat and not to open any PDF documents from unknown users or sources.  

To Disable JavaScript in Acrobat Reader:

Click: Edit -> Preferences -> JavaScript(left panel) and uncheck Enable Acrobat JavaScript

For more information, please visit these websites:

http://blogs.zdnet.com/security/?p=5119
http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214
http://threatpost.com/en_us/blogs/how-mitigate-adobe-pdf-malware-attacks-030609