Threat behavior
Exploit:Win32/Pdfjsc.ER is a detection for specially-crafted PDF files that attempt to exploit software vulnerabilities in Adobe Acrobat and Adobe Reader.
These PDF files contain an embedded JavaScript that, when loaded (as when the files are opened in a vulnerable version of Adobe Acrobat or Adobe Reader) executes a shellcode that exploits the vulnerabilities. The shellcode may perform any action, such as downloading and running other malware.
The vulnerabilities Exploit:Win32/Pdfjsc.ER attempts to exploit are the following:
Exploit:Win32/Pdfjsc.ER usually arrives in the system when the user visits a Web page that contains a malicious PDF file or opens an e-mail message containing the PDF file as an attachment.
Analysis by Vincent Tiu
Prevention