Adobe Acrobat Vulnerabilities Exposed Govt Data
Russian federal agency FSTEC discovered three critical vulnerabilities in Adobe Acrobat for Windows and macOS that could allow attackers to steal documents from government computers via malicious PDF files. Despite Adobe's exit from Russia and blocking of Russian accounts, its software remains in use by Russian state institutions.
Consensus
- FSTEC discovered three critical vulnerabilities in Adobe Acrobat affecting Windows and macOS.
- Malicious PDF files can be used to steal documents from Russian government computers.
- Attackers can impersonate legitimate documents by inserting malicious code while preserving text and stamps.
- Opening the compromised PDF grants access to computer memory and allows extraction of stored PDF files.
- Russian government agencies spent over 16.4 million rubles on Adobe products in the past year.
- Adobe has separate government contracts with the United States worth about 780 million dollars.
- Adobe has exited Russia and blocked Russian accounts, but its software is still used by Russian state bodies.
Coverage (2 sources)
- Adobe Acrobat vulnerabilities found for Windows and macOS — РИАМО
- Adobe Acrobat may leak documents from Russian government computers via malicious PDFs — FSTEC found three dangerous vulnerabilities in the program for Windows and macOS — Mash