Adobe Acrobat May Block Antivirus Tools From Having Visibility Into PDF files

Share post:

Adobe Acrobat may block security software from having visibility into the PDF files it opens. This could pose a security risk to users as it prevents these antivirus tools from monitoring for malicious activity.

The process have however been disrupted after Adobe Acrobat Reader tried to query which security product DLLs are loaded into it by acquiring a handle of the DLL.

“March of 2022 we’ve seen a gradual uptick in Adobe Acrobat Reader processes attempting to query which security product DLLs are loaded into it by acquiring a handle of the DLL,” Minerva Lab said.

According to Minerva researchers, the list now includes 30 DLLs from security products from various vendors. The most popular DLLs include Bitdefender, Avast, Trend Micro, Symantec, Malwarebytes, ESET, Kaspersky, F-Secure, Sophos and Emsisoft.

In the past, PDF files acted as vectors for attackers to execute malware on the system. According to researchers at Minerva Labs, attackers use the method to add a command in the ‘OpenAction’ section of the document to execute PowerShell commands for malicious activity.

It is important that antivirus software tools get visibility into all processes on the system. This is achieved by injecting dynamic-link libraries (DLLs) into software products launching on the machine.

Adobe acknowledged the problem and explained that it occurred due to DLL components of some security products that are not compatible with Adobe Acrobat’s use of the CEF library.

The company said it was working with the affected providers to assess the issue.

The sources for this piece include an article in BleepingComputer.

SUBSCRIBE NOW

Related articles

Sleeper Supply Chain Attack Activates After 6 Years

A coordinated supply chain attack has compromised between 500 and 1,000 e-commerce websites by exploiting vulnerabilities in 21...

Russian-Controlled Open Source Tool Raises Alarms Over U.S. Cybersecurity

A widely used open-source Go library, easyjson, used in healthcare, finance and even defence has come under scrutiny...

Signal Archiving Tool Used By Trump Admin Is Breached, Raising Alarms Over Messaging Security (EDITORIAL)

(EDITORIAL) A messaging tool used by Trump administration officials to archive encrypted Signal messages has been hacked —...

Anthropic Warns: AI “Virtual Employees” Could Pose Security Risks Within a Year

Anthropic, a leading artificial intelligence company, anticipates that AI-powered virtual employees could begin operating within corporate networks as...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways