A program or technique that takes advantage of a vulnerability to remotely access or attack a program, computer or server.
Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.
The detection Exploit:W32/AdobeReader.UZ identifies a malicious PDF document that attempts to exploit a known vulnerability in order to drop and run a malicious executable file on the system.
The exploit-code will not drop the executable if any of the following folders exist on the system:
- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009
- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009
- C:\Program Files\Kingsoft
The executable file embedded in the PDF will be dropped to:
The dropped file will then be executed and will attempt to download additional files on to the system.
We detect the drooped file as Trojan-Downloader:W32/Agent.MRL.