We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Exploit:Win32/Pdfjsc.AEW
Aliases: EXP/Pdfjsc.aew (Avira) Exploit.JS.PDF.FE (BitDefender) Exploit.PDF (Ikarus) Exploit.PDF.3072 (Dr.Web) Exploit-PDF!Blacole.o (McAfee) Exploit-PDF.bo.gen (McAfee) JS/Exploit.Pdfka.PWH (ESET) JS/Pdfka.JB (Command) Pdfka.BN (Norman) Troj/PDFJs-AAS (Sophos) Exploit_c.WAH (AVG)
Summary
Exploit:Win32/Pdfjsc.AEW is a malicious PDF file that exploits a vulnerability in Adobe Acrobat and Adobe Reader.
The vulnerabilities, discussed in CVE-2010-0188, allow this malware to download and run arbitrary files.
The following versions of Adobe Acrobat and Adobe Reader are vulnerable to this exploit:
- Adobe Acrobat and Adobe Reader earlier than 8.2.1
- Adobe Acrobat and Adobe Reader earlier than 9.3.1
Install updates to prevent infection
This malware exploits known vulnerabilities.
You should always install the latest updates available from the software vendor to prevent reinfection from this threat, and possible infection from other threats.
Download updates for Adobe products from the following link:
To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:
- Microsoft Security Essentials or, for Windows 8, Windows Defender
- Microsoft Safety Scanner
Update vulnerable PDF applications
This threat exploits known vulnerabilities in Adobe Acrobat and Adobe Reader. After removing this threat, make sure that you install the updates available from the vendor. You can read more about these vulnerabilities in PDF documents, as well as where to download the software update, from the following links: