McAfee said it has found a vulnerability in Adobe Systems’ Reader program that reveals when and where a PDF document is opened.
The issue is not a serious problem and does not allow for remote code execution, wrote McAfee’s Haifei Li in a blog post. But McAfee does consider it a security problem and has notified Adobe. It affects every version of Adobe Reader, including the latest version, 11.0.2, Li wrote.
McAfee recently detected some “unusual” PDF samples, Li wrote. McAfee withheld some key details of the vulnerability, but did generally describe it.
Li suggests the problem could be used for reconnaissance by attackers.
“Some people might leverage this issue just out of curiosity to know who has opened their PDF documents, but others won’t stop there,” Li wrote. “An APT [advanced persistent threat] attack usually consists of several sophisticated steps. The first step is often collecting information from the victim; this issue opens the door.”