Home / malwarePDF  

Exploit:W32/AdobeReader.UZ


First posted on 15 January 2010.
Source: SecurityHome

Aliases :

There are no other names known for Exploit:W32/AdobeReader.UZ.

Explanation :

A program or technique that takes advantage of a vulnerability to remotely access or attack a program, computer or server.

Additional DetailsThe detection Exploit:W32/AdobeReader.UZ identifies a malicious PDF document that attempts to exploit a known vulnerability in order to drop and run a malicious executable file on the system.

The exploit-code will not drop the executable if any of the following folders exist on the system:

€ C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009 € C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009 € C:\Program Files\Kingsoft
The vulnerability targeted lies in the Doc.media.newPlayer Javascript method (CVE-2009-4324).

Execution

The executable file embedded in the PDF will be dropped to:

€ %temp%\AdobeUpdate.exe
The dropped file will then be executed and will attempt to download additional files on to the system.

We detect the drooped file as Trojan-Downloader:W32/Agent.MRL.

Last update 15 January 2010

 

TOP