当前位置:网站首页>Adobe Acrobat prevents 30 security software from viewing PDF files or there are security risks

Adobe Acrobat prevents 30 security software from viewing PDF files or there are security risks

2022-06-26 12:53:00 Chinese industry information station

PDF Files have been misused in the past to execute malware on the system . Network security company Minerva Labs The researchers explained that , One way is in the documentation “OpenAction” Section to add a command to run PowerShell Command to carry out malicious activities .

Minerva Labs Express :“ since 2022 year 3 Since the month , We see Adobe Acrobat Reader Gradual increase of process , Try to get DLL To query which security products are loaded DLL”.

According to a report this week , The list has grown to include security products from different vendors 30 individual DLL. More popular with consumers are Bitdefender、Avast、 The trend of science and technology 、 symantec 、Malwarebytes、ESET、 kaspersky 、F-Secure、Sophos、EMSIsoft.

The list is as follows :

  1. Trend Micro

  2. BitDefender 

  3. AVAST 

  4. F-Secure

  5. McAfee

  6. 360 Security

  7. Citrix

  8. Symantec

  9. Morphisec

  10. Malwarebytes

  11. Checkpoint

  12. Ahnlab

  13. Cylance

  14. Sophos

  15. CyberArk

  16. Citrix

  17. BullGuard

  18. Panda Security

  19. Fortinet

  20. Emsisoft

  21. ESET

  22. K7 TotalSecurity

  23. Kaspersky

  24. AVG

  25. CMC Internet Security

  26. Samsung Smart Security ESCORT

  27. Moon Secure

  28. NOD32

  29. PC Matic

  30. SentryBay

The query system is through “libcef.dll” Accomplished , This is a program used by various programs Chromium Embedded Framework (CEF) Dynamic link library . although Chromium DLL A short list of components is attached , They are blacklisted because they can lead to conflict , But vendors using it can make changes and add whatever they want DLL.

The researchers explained ,“libcef.dll By two Adobe Process load :AcroCEF.exe and RdrCEF.exe”, Therefore, both products are checking whether there are components of the same security product in the system .

Observe the injection carefully Adobe Process DLL What's going to happen ,Minerva Labs Find out Adobe Check registry key “SOFTWARE\Adobe\Adobe Acrobat\DC\DLLInjection\” Under the bBlockDllInjection Whether the value is set to 1. If it is , It will prevent anti-virus software from DLL Injected process .

according to Minerva Labs researcher Natalie Zargarov That's what I'm saying , The default value of the registry key is set to “1”—— Indicates active blocking . This setting may depend on the operating system or the installed Adobe Acrobat edition , And other variables on the system .

Adobe Reply BleepingComputer Time confirmation , The user has reported... Due to some security products DLL Components and Adobe Acrobat Yes CEF Problems caused by incompatible use of Libraries .

Adobe Express :“ We know that there are reports that some of the security tools DLL And Adobe Acrobat Yes CEF The use of is incompatible ,CEF It's based on Chromium The engine of , With limited sandbox design , And may cause stability problems ”.

The company added , It is currently working with these suppliers to solve this problem , and “ Ensure the future Acrobat Of CEF Sandbox design has the right function .”Minerva Labs The researchers believe that ,Adobe The solution chosen can solve the compatibility problem , But by preventing the security software protection system, the real attack risk is introduced .

原网站

版权声明
本文为[Chinese industry information station]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/177/202206261119468928.html