{"id":139576,"date":"2022-05-18T23:02:21","date_gmt":"2022-05-19T04:02:21","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2022\/05\/new-tool-to-find-vulnerabilities-in-the-way-applications-like-microsoft-word-and-adobe-acrobat-process-javascript-cooperative-mutation-attack"},"modified":"2022-05-18T23:02:21","modified_gmt":"2022-05-19T04:02:21","slug":"new-tool-to-find-vulnerabilities-in-the-way-applications-like-microsoft-word-and-adobe-acrobat-process-javascript-cooperative-mutation-attack","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2022\/05\/new-tool-to-find-vulnerabilities-in-the-way-applications-like-microsoft-word-and-adobe-acrobat-process-javascript-cooperative-mutation-attack","title":{"rendered":"New tool to find vulnerabilities in the way applications like Microsoft Word and Adobe Acrobat process JavaScript: Cooperative mutation attack"},"content":{"rendered":"<p><\/p>\n<p><iframe style=\"display: block; margin: 0 auto; width: 100%; aspect-ratio: 4\/3; object-fit: contain;\" src=\"https:\/\/www.youtube.com\/embed\/-plvKXjb_CY?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; encrypted-media; gyroscope;\n   picture-in-picture\" allowfullscreen><\/iframe><\/p>\n<p>A group of researchers developed a tool capable of detecting errors in the way applications such as <strong>Adobe Acrobat<\/strong> or <strong>Microsoft Word<\/strong> process <strong><a href=\"https:\/\/www.securitynewspaper.com\/2022\/03\/29\/node-ipc-javascript-library-was-modified-to-include-file-deletion-malware-depending-on-the-users-ip-addresses\/\" target=\"_blank\" rel=\"noreferrer noopener\">JavaScript<\/a><\/strong> code, which has allowed finding a total of 134 security flaws, of which 33 have already received a <strong><a href=\"https:\/\/www.securitynewspaper.com\/2022\/01\/26\/new-linux-lpe-vulnerability-affects-millions-of-ubuntu-debian-centos-and-fedora-servers-worldwide-exploit-code-published\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE tracking key<\/a><\/strong>.<\/p>\n<p>The tool is called <strong><em>\u201cCooper\u201d<\/em><\/strong>, in reference to the technique known as \u201cCooperative Mutation\u201d it employees. <strong><a href=\"https:\/\/huhong789.github.io\/papers\/xu: cooper.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Xu Peng<\/a><\/strong>, a software development specialist and co-author of the tool, explains that tools like the ones mentioned accept information from scripting languages; for example, Acrobat allows JavaScript to manipulate PDF files.<\/p>\n<p>This requires the PDF to define native PDF objects and parse the JavaScript code. Native objects are processed by Acrobat modules and a built-in JavaScript engine handles the scripts, while a \u201cbinding layer\u201d does the translation.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A group of researchers developed a tool capable of detecting errors in the way applications such as Adobe Acrobat or Microsoft Word process JavaScript code, which has allowed finding a total of 134 security flaws, of which 33 have already received a CVE tracking key. The tool is called \u201cCooper\u201d, in reference to the technique [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1492],"tags":[],"class_list":["post-139576","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/139576","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=139576"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/139576\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=139576"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=139576"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=139576"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}