Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Report: Adobe Reader is blocking antivirus tools from scanning loaded PDF documents
#1
Information 
Quote:Adobe is blocking several antivirus tools actively from scanning PDF documents loaded by its Adobe Acrobat Reader application, according to a security report published by Minerva Labs.

[Image: adobe-acrobat-reader-security-compatibility-issue.png]

The company found evidence that Adobe is blocking around 30 different security products from scanning loaded PDF documents. The list reads like the who is who of security companies, with one notable exception. Products from Trend Micro, McAfee, Symantec, ESET, Kaspersky, Malwarebytes, Avast, BitDefender and Sophos are blocked, according to the report. The one notable exception, at least from a market share point of view, is Microsoft Defender, which is not blocked by Adobe's software.

Here is the full list of affected companies and products:
 
Quote:Trend Micro, BitDefender, AVAST, F-Secure, McAfee, 360 Security, Citrix, Symantec, Morphisec, Malwarebytes, Checkpoint, Ahnlab, Cylance, Sophos, CyberArk, Citrix, BullGuard,  Panda Security, Fortinet, Emsisoft, ESET, K7 TotalSecurity, Kaspersky, AVG, CMC Internet Security, Samsung Smart Security ESCORT, Moon Secure, NOD32, PC Matic, SentryBay

Blocked products are denied access to the loaded PDF file, which means that malicious code can't be detected or stopped by the products during the loading phase.

Security tools inject DLLs, Dynamic Link Libraries, into applications that are launched on the system, which is necessary to gain access. The blocking prevents the injection from taking place.

Adobe Acrobat uses the Chromium Embedded Framework (CEF) Dynamic Link Library, Libcef.dll, in two processes according to the report. The Chromium component includes a blacklist of its own to prevent issues and conflicts with DLL files. Software companies, who use libcef.dll, may customize the blacklist, and it appears that Adobe has done that to add the DLL files of security products to it.

Minerva Labs notes that the outcome of the blocking "could potentially be catastrophic". Besides reduced visibility, which "hinders detection and prevention capabilities inside the process and inside every created child processes", it is limiting the security application's means to monitor activity and to determine context.
 
Quote:It would be easy enough for a threat actor to add a command in the ‘OpenAction’ section of a pdf, which can then execute PowerShell, which could for example, download the next stage malware and execute it reflectively. Any of these actions would not be detected if the security product hooks are missing.

Minerva Labs contacted Adobe to find out why security products are blocked by Adobe Acrobat. Adobe replied that 'this is due to "incompatibility with Adobe Acrobat’s usage of CEF, a Chromium based engine with a restricted sandbox design, and may cause stability issues"'.

In other words: Adobe has chosen to address stability issues by blocking security processes. Minerva Labs points out that Adobe picked convenience and the insertion of a "malware-like" behavior over resolving the issue permanently.

Bleeping Computer received a similar answer when the site contacted Adobe. Adobe confirmed that it was working with vendors of the security products to address the incompatibilities and to "ensure proper functionality with Acrobat's CEF sandbox design going forward".

Now You: do you use Adobe Acrobat Reader or another PDF application?
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
GFYI [Official] Ashampoo Snap 16 Giveaw...
GIVEAWAY / CONTEST I...jasonX — 06:19
GFYI [Official] VTubeGo Downloader 2004...
GIVEAWAY / CONTEST I...jasonX — 06:19
GFYI [Official] Wise Video Converter Pr...
We are pleased to an...jasonX — 06:17
GFYI [Official] EaseUS Data Recovery Wi...
We are pleased to an...jasonX — 06:17
Mozilla Firefox Browser 125.0
Mozilla Firefox Br...harlan4096 — 06:16

[-]
Birthdays
Today's Birthdays
avatar (48)fuspeukChark
avatar (42)werriewWaiNg
avatar (36)Freemanleo
Upcoming Birthdays
avatar (43)wapedDow
avatar (47)oapedDow
avatar (40)Sanchowogy
avatar (42)techlignub
avatar (41)Stevenmam
avatar (48)onlinbah
avatar (49)steakelask
avatar (43)Termoplenka
avatar (41)bycoPaist
avatar (47)pieloKat
avatar (41)ilyagNeexy
avatar (49)donitascene
avatar (49)Toligo
avatar (36)RobertUtelt

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>