📜 ⬆️ ⬇️

PDF files are infectious when you hover over them

Adobe has not yet closed the / JBIG2Decode vulnerability in PDF documents, and hackers are finding new ways to use it. It turns out that it can be done so that the malicious code will be executed on the computer even without opening the file, but simply when interacting with the Windows Explorer Shell extension , the special Column Handler Shell Extension COM object, which is embedded in the native Windows shell when installing Adobe Reader.

That is, malicious code will be executed, for example, when you select a file with one click of the mouse or simply when you hover the cursor on it in Windows Explorer. The video shows how this happens. Details about the exploit, see its author .


')
PS They say Adobe is planning to release a patch on March 11th.

Source: https://habr.com/ru/post/53910/


All Articles