Reader has been criticised for its security failings, with Microsoft accusing such third-party apps of being “easier pickings” than Windows itself.
Adobe Reader Protected Mode will arrive in the next update of the PDF software. It will make use of the “sandbox” technique, preventing attacks via Reader from touching the rest of the computer.
Famously used by Google’s Chrome browser, sandboxing isolates the code from the rest of the system so the damage from attacks is limited.
“Even if an exploitable security vulnerability is found by an attacker, Adobe Reader Protected Mode will help prevent the attacker from writing files, changing registry keys or installing malware on potential victims’ computers,” said Brad Arkin, director of product security and privacy, in a post on the Adobe Security blog.
Any operations that need to happen outside the sandbox, such as opening an attachment or saving to a computer, are first run past a “strict set of policies” to make sure nothing dangerous is being done.
Adobe said its Reader sandbox is based on Microsoft’s system for Windows, and that it worked with Microsoft Office and Chrome teams to create its own.
Protected Mode will be enabled by default, and initially sandbox only “write” calls in Windows systems. “In future releases of Adobe Reader, we plan to extend the sandbox to include read-only activities to protect against attackers seeking to read sensitive information on the user’s computer,” Arkin added.





Subscribers 0
Fans 0
Followers 0
Followers