Security researcher Didier Stevens has developed a proof-of-concept PDF file that executes an embedded executable without making use of any vulnerabilities.
"The PDF hack, when combined with clever social engineering techniques, could potentially allow code execution attacks if a user simply opens a rigged PDF file," writes ZDNet's Ryan Naraine.
"Stevens said Adobes PDF Reader will block the file from automatically opening but he warned that an attacker could use social engineering tricks to get users to allow the file to be opened," Naraine writes.
Click here to read the ZDNet article.
Loading Comments...