1 Trillion Dollar Refund: How To Spoof PDF Signatures
Vladislav Mladenov, Christian Mainka, Karsten Meyer zu Selhausen, Martin Grothe, Jörg Schwenk
Abstract
The Portable Document Format (PDF) is the de-facto standard for document exchange worldwide. To guarantee the authenticity and integrity of documents, digital signatures are used. Several public and private services ranging from governments, public enterprises, banks, and payment services rely on the security of PDF signatures. In this paper, we present the first comprehensive security evaluation on digital signatures in PDFs. We introduce three novel attack classes which bypass the cryptographic protection of digitally signed PDF files allowing an attacker to spoof the content of a signed PDF. We analyzed 22 different PDF viewers and found 21 of them to be vulnerable, including prominent and widely used applications such as Adobe Reader DC and Foxit. We additionally evaluated eight online validation services and found six to be vulnerable. A possible explanation for these results could be the absence of a standard algorithm to verify PDF signatures -each client verifies signatures differently, and attacks can be tailored to these differences. We, therefore, propose the standardization of a secure verification algorithm, which we describe in this paper. All findings have been responsibly disclosed, and the affected vendors were supported during fixing the issues. As a result, three generic CVEs for each attack class were issued [50] [51] [52] . Our research on PDF signatures and more information is also online available at https://www.pdf-insecurity.org/ .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext db3659fe-ac6d-478b-853b-90ef1ff253b4Cited by top-tier papers5
- Practical Decryption exFiltration: Breaking PDF EncryptionJens Müller, Fabian Ising, Vladislav Mladenov, Christian Mainka et al.CCS 2019 · 18 citations
- Breaking the Specification: PDF CertificationSimon Rohlmann, Vladislav Mladenov, Christian Mainka, Jörg SchwenkS&P 2021 · 16 citations
- Every Signature is Broken: On the Insecurity of Microsoft Office's OOXML SignaturesSimon Rohlmann, Vladislav Mladenov, Christian Mainka, Daniel Hirschberger et al.USENIX Security 2023
- Shadow Attacks: Hiding and Replacing Content in Signed PDFsChristian Mainka, Vladislav Mladenov, Simon RohlmannNDSS 2021
- Oops... Code Execution and Content Spoofing: The First Comprehensive Analysis of OpenDocument SignaturesSimon Rohlmann, Christian Mainka, Vladislav Mladenov, Jörg SchwenkUSENIX Security 2022
Builds on3
- Extract Me If You Can: Abusing PDF Parsers in Malware DetectorsCurtis Carmony, Xunchao Hu, Heng Yin, Abhishek Vasisht Bhaskar et al.NDSS 2016 · 61 citations
- Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie PoliciesGertjan Franken, Tom van Goethem, Wouter JoosenUSENIX Security 2018 · 39 citations
- PDF Mirage: Content Masking Attack Against Information-Based Online ServicesIan D. Markwood, Dakun Shen, Yao Liu, Zhuo LuUSENIX Security 2017 · 31 citations
Related papers
- Processing Dangerous Paths - On Security and Privacy of the Portable Document FormatJens Müller, Dominik Noss, Christian Mainka, Vladislav Mladenov et al.NDSS 2021
- "Johnny, you are fired!" - Spoofing OpenPGP and S/MIME Signatures in EmailsJens Müller, Marcus Brinkmann, Damian Poddebniak, Hanno Böck et al.USENIX Security 2019 · 34 citations
- From Documentation to Zero-day Vulnerabilities: LLM-Driven Fuzzing of JavaScript Engines in PDF ReadersSuyue Guo, Stijn Pletinckx, Tianle Yu, Yigitcan Kaya et al.CCS 2026
- Morpheus: Bringing The (PKCS) One To Meet the OracleMoosa Yahyazadeh, Sze Yiu Chau, Li Li, Man Hong Hue et al.CCS 2021 · 5 citations
- Iframes/Popups Are Dangerous in Mobile WebView: Studying and Mitigating Differential Context VulnerabilitiesGuangliang Yang, Jeff Huang, Guofei GuUSENIX Security 2019 · 21 citations
