|Skip to Main Content|
  1. PROSPECTIVE STUDENTS
  2. CURRENT STUDENTS
  3. FACULTY & STAFF
  4. ALUMNI
  5. COMMUNITY & FRIENDS
 
  1. CAMPUS LINKS
    1. Inside UNCG
    2. Admissions
    3. Academics
    4. Libraries
    5. Administration
    6. Research & Centers
    7. International Programs
    8. Continuing Education
      & Outreach
    9. Technology
    10. Arts & Entertainment
    11. Employment
    12. Corporate Resources
    13. Giving to UNCG

Information Technology Services

Home » News » 2007 » October » PDF Security Vulnerability

PDF Security Vulnerability

25 October 2007

Who: Campus Community

What: PDF Security Vulnerability


Background: A vulnerability in the mailto handling of Adobe Acrobat and Adobe Reader for Windows allows remote attackers to execute arbitrary code via a specially crafted PDF file.

Impact: Due to the wide-spread use of PDFs, the possibility exists for numerous systems to be exploited and for existing threats such as Storm Worm to exploit this vulnerability in the near future.

Platforms Affected: Users running Windows XP with Internet Explorer 7 installed (Vista is not affected)

Local Observations: The Information Technology Services (ITS) Security group has not seen active exploitation of this vulnerability on university systems, but is
aware that the vulnerability is currently being exploited on the Internet at large.

Recommendations: Apply updates from Adobe. Open Adobe Acrobat production and look for the update option under the help drop down menu. Or install new version of the product and apply the updates:

Workarounds: Uninstall affected products and restart Windows

Further Reading:

If you have questions, please contact 6-TECH at (336) 256-TECH (8324).

 
Information Technology Services
The University of North Carolina at Greensboro

Greensboro, NC 27402-6170
Technical Support 336.256.TECH (8324)