Adobe Reader contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker calls the .LoadFile() method exposed by ActiveX in Internet Explorer via a malicious web page to trigger a flaw in Adobe Reader and disclose information on existence of local files in the target system resulting in a loss of confidentiality.
Classification
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Unavailable
Technical
.LoadFile() is a method exposed by ActiveX in Internet Explorer which takes filename as the argument. Hence the existence of local files can be discovered only if the complete pathnames and filenames are known to the attacker in advance.
The contents of the files can't be accessed.
An attack can take place only when the recipient opens PDF documents directly with Internet Explorer via Adobe Web Control Active X object.
Solution
Upgrade to version 7.0.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.