PDF exploit is not that common in recent years especially with the introduction of Protected Mode that adds sandbox protection. However, the CVE-2013-0640 exploits were
the first known attacks that can bypass the sandbox of Protected Mode in Reader XI and Acrobat XI for Windows (Protected View is not enabled by default for these versions), and cause the application
to crash and potentially allow an attacker to take control of the
affected system.
Earlier this month, Xecure Lab captured the CVE-2013-0640 PDF exploit in an APT email attack. The malicious PDF was disguised in the form of datasheet, wrapped in rar and further protected with password. The password of "1234567890" was provided in the email body for the target to open it easily.



