InfoTechTarget and Informa Tech's Digital Businesses Combine.

Together, we power an unparalleled network of 220+ online properties covering 10,000+ granular topics, serving an audience of 50+ million professionals with original, objective content from trusted sources. We help you gain critical insights and make more informed decisions across your business priorities.

Vulnerability Hunting in a Third-Party Plugin in Adobe Acrobat Through Fuzzing

Presented by

Kai Lu, Principal Security Researcher at Zscaler

About this talk

In today’s cybersecurity landscape, zero-day vulnerabilities pose significant threats to software applications, and their discovery is crucial for effective mitigations. Join us in this webinar as we will share our journey in uncovering vulnerabilities in Adobe Acrobat and Foxit PDF Editor, the two most widely used PDF processing applications. • Develop a custom harness to fuzz the Solid Framework, a third-party library used by Adobe Acrobat and Foxit PDF Editor for PDF document to Microsoft Office document file conversion. • Discovered and reported 16 vulnerabilities to date, including six cases in Adobe Acrobat and ten cases in Foxit PDF Editor, with all cases fixed. • Notably, five of these vulnerabilities impacted both Adobe Acrobat and Foxit PDF Editor, highlighting the potential ripple effects of vulnerabilities in third-party libraries. • Share insights into our vulnerability-hunting journey, including the techniques used, and the impact of our discoveries. • Discuss the ethical considerations in vulnerability hunting and responsible disclosure practices. • Educate software developers about the risks that third-party and open-source libraries pose when used without a thorough security code audit via fuzzing. Join us to learn from our experiences and gain valuable insights into uncovering vulnerabilities in PDF processing applications. Don’t miss out on the opportunity to enable your knowledge of vulnerability hunting and responsible disclosure practices.
Zscaler

Zscaler

32372 subscribers252 talks
Zero Trust + AI: Protecting What Firewalls Can't
Traditional firewalls, VPNs, and public point solutions for data security are failing in the AI era, because they expand your attack surface and allow lateral threat movement. The Zero Trust Exchange delivers a new approach that eliminates the concept of implicit trust, operating on the principle: Never trust, always verify. It delivers zero trust architecture as a service from a resilient, cloud-native AI cybersecurity platform. Acting as an intelligent switchboard to enable Zero Trust Everywhere, it provides secure, any-to-any, zero trust communication that uses business policies, not networks, for all of your workforces, branches, and clouds. The platform, built upon the Zero Trust Architecture and AI foundation, provides five integrated solutions: Cyberthreat Protection, Data Security, Zero Trust Branch and Cloud, and Security Operations.
Related topics