Adobe Acrobat may block antivirus tools from monitoring PDF files

Gandalf_The_Grey

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Forum Veteran
Apr 24, 2016
7,806
6
82,950
8,389
55
The Netherlands
Security researchers found that Adobe Acrobat is trying to block security software from having visibility into the PDF files it opens, creating a security risk for the users.

Adobe’s product is checking if components from 30 security products are loaded into its processes and likely blocks them, essentially denying them from monitoring for malicious activity.
Replying to BleepingComputer, Adobe confirmed that users have reported experiencing issue due to DLL components from some security products being incompatible with Adobe Acrobat’s usage of the CEF library.

“We are aware of reports that some DLLs from security tools are incompatible with Adobe Acrobat’s usage of CEF, a Chromium based engine with a restricted sandbox design, and may cause stability issues” - Adobe

The company added that it is currently working with these vendors to address the problem and “to ensure proper functionality with Acrobat's CEF sandbox design going forward.”
 
Here is the full list of affected companies and products:

Trend Micro, BitDefender, AVAST, F-Secure, McAfee, 360 Security, Citrix, Symantec, Morphisec, Malwarebytes, Checkpoint, Ahnlab, Cylance, Sophos, CyberArk, Citrix, BullGuard, Panda Security, Fortinet, Emsisoft, ESET, K7 TotalSecurity, Kaspersky, AVG, CMC Internet Security, Samsung Smart Security ESCORT, Moon Secure, NOD32, PC Matic, SentryBay
 
So, not a problem for Microsoft Defender?
MD looks like unaffected, at least according to this report from ghacks. EDIT: Researchers main report shows the same list, so even there MD looks like unaffected.

The one notable exception, at least from a market share point of view, is Microsoft Defender, which is not blocked by Adobe's software.
 
MD looks like unaffected, at least according to this report from ghacks. EDIT: Researchers main report shows the same list, so even there MD looks like unaffected.


Great because we use Defender (for endpoint) at work together with Adobe Reader.
Maybe time to use Defender at home again :unsure:
 
  • Like
Reactions: silversurfer