Automatically translated.View original post

Don't forget to update Acrobat. 🚨

Adobe released an urgent security update to fix the Zero-Day vulnerability in Acrobat and Acrobat Reader that has been used to attack it since last December. This weakness is highly dangerous. Because users can open a PDF file immediately without doing anything to add Zero Click.

.

The vulnerability is tracked as CVE-2026-34621. The severity follows CVSSv3 8.6 / 10 points. It is caused by the fact that some PDF files that have been embedded by the virus can be dropped from the program's sandbox system and run a highly eligible JavaScript API. This results in the attacker being able to access local files, read critical data, or run additional malicious code.

.

According to the analysis, the vulnerability uses functions like util.readFileIntoStream () to read local files, and uses RSS.addFeed () to send data out to the hacker's server, as well as to extract additional code into the maran in the victim's system.

.

This vulnerability was discovered by Haifei Li, founder of the EXPMON detection system. The latter had sample file senders come in to analyze it. In the early days malware evaded the protection system very well. Only 5 of the 64 systems detected it, making the attack easy to spread.

.

Adobe states that this vulnerability affects both Windows and macOS. It covers several versions of Acrobat and Reader that have not been updated. It recommends that users update the software immediately via the Help > Check for Updates menu or download it from the official website, as there is no way to protect it other than to install patches.

.

- Acrobat DC and Acrobat Reader DC version 26.001.21367 and earlier, update to version 26.001.21411 or later

- Acrobat 2024 version 24.001.30356 and earlier, update to version 24.001.30362 for Windows and 24.001.30360 for macOS or later versions

.

Users should avoid opening PDF files from unreliable sources and should use them in a secure environment to reduce the risk of this type of attack.

.

Source: neowin

# IT should know # IT News # Includes IT matters # IT

4/20 Edited to

... Read moreจากประสบการณ์ที่ผมเคยพบเจอมากับตัวเอง การละเลยการอัปเดตซอฟต์แวร์ทำให้เครื่องคอมพิวเตอร์เสี่ยงต่อการถูกโจมตีได้ง่ายขึ้นอย่างมาก โดยเฉพาะโปรแกรมที่ใช้เปิดไฟล์ PDF อย่าง Adobe Acrobat ที่มีโอกาสโดนมัลแวร์ฝังไวรัสผ่านช่องโหว่แบบ Zero-Day ซึ่งครั้งนี้มีความรุนแรงถึง 8.6 คะแนนตามมาตรฐาน CVSSv3 สำหรับผู้ใช้งานทั่วไป สิ่งที่สำคัญที่สุดคือการอย่าประมาทกับไฟล์ PDF ที่ได้รับมาจากแหล่งที่ไม่น่าเชื่อถือ เพราะมัลแวร์สามารถทำงานทันทีเมื่อเปิดไฟล์นั้นโดยไม่ต้องคลิกอะไรเพิ่มเติม (Zero Click) ซึ่งแตกต่างจากการโจมตีในรูปแบบอื่นๆ ที่ต้องมีการโต้ตอบจากผู้ใช้ ในด้านเทคนิค ช่องโหว่นี้เกิดจากฟังก์ชัน util.readFileIntoStream() ที่อนุญาตให้ไฟล์ PDF สามารถเข้าถึงไฟล์ภายในเครื่องได้ และใช้ RSS.addFeed() ในการส่งข้อมูลกลับไปยังเซิร์ฟเวอร์ของแฮกเกอร์ ซึ่งถือเป็นช่องโหว่ที่สูงมากเพราะยังใช้ฟีเจอร์ JavaScript API ที่มีสิทธิ์สูงในโปรแกรม Acrobat ทำให้แฮกเกอร์สามารถรันโค้ดอันตรายในเครื่องของเหยื่อได้โดยง่าย ที่สำคัญก็คือ Adobe ได้ออกแพตช์แก้ไขแล้วทั้งบน Windows และ macOS ควรรีบตรวจสอบและอัปเดตเวอร์ชันโปรแกรมให้เป็นเวอร์ชันล่าสุดทันทีผ่านเมนู Help > Check for Updates หรือติดตั้งไฟล์ติดตั้งจากเว็บไซต์ทางการตามเวอร์ชันที่กำหนดไว้ เพื่อปิดช่องโหว่นี้โดยเร็วที่สุด นอกจากนี้สำหรับผู้ที่ทำงานในองค์กร สิ่งที่ควรทำคือการสร้างมาตรการในการสแกนไฟล์ PDF ที่รับเข้ามาอย่างเข้มงวด รวมถึงอบรมผู้ใช้งานให้มีความระมัดระวังไม่เปิดไฟล์หรือเอกสารจากแหล่งที่ไม่พิสูจน์ได้ การใช้ระบบ Sandboxing และ Antivirus ที่มีประสิทธิภาพก็ช่วยลดความเสี่ยงลงได้อย่างมาก สุดท้ายแล้ว ช่องโหว่นี้ถือเป็นบทเรียนสำคัญว่า “การอัปเดตซอฟต์แวร์อย่างสม่ำเสมอ” คือขั้นตอนป้องกันที่ดีสุดสำหรับทุกคนที่ใช้งานคอมพิวเตอร์ และการรู้เท่าทันภัยคุกคามทางไซเบอร์จะช่วยให้เราสามารถปกป้องข้อมูลส่วนตัวและระบบได้ดีที่สุด