Zeus Exploiting Unpatched PDF Flaw

Zeus exploits the "/Launch" design flaw to embed attack code in the document.

By Kara Reeder | Posted Apr 16, 2010
Print ArticleEmail Article
  • Share on Facebook
  • Share on Twitter
  • Share on LinkedIn
According to Computerworld, the Zeus botnet is now making use of an unpatched flaw in Adobe's PDF document format discovered by security researcher Didier Stevens.

Zeus exploits the "/Launch" design flaw to embed attack code in the document. The article explains:

When users open the rogue PDF, they're asked to save a PDF file called 'Royal_Mail_Delivery_Notice.pdf.' That file, however, is actually a Windows executable that when it runs, hijacks the PC.

This may be the beginning of the PDF attack wave predicted by Mickey Boodaei, CEO of security company Trusteer.

Comment and Contribute
(Maximum characters: 1200). You have
characters left.
Get the Latest Scoop with Enterprise Networking Planet Newsletter