An independent security researcher and penetration tester at SecRecon has published a tool (the PDF Exploit Generator) specifically designed to bring various exploits that can be used in PDF files.
The utility is useful for activity monitoring, but it could also cause significant damage to users working with unpatched versions of Adobe Reader and Acrobat if it falls into the wrong hands.
According to Darren Pauli from The Register, the tool is fully functional “in versions of Adobe Reader and Acrobat 8.x prior to 8.2.1 and 9.3.1 9.x.”
Even though it can only be used with old exploits for vulnerabilities that have been reported in the latest updated versions of the two products, there may still be many who have not upgraded their programs. It is, of course, unnecessary to mention that they are at risk.
The tool has been named (as we mentioned earlier) PDF Exploit Generator and supports URL input, in order to provide exploited PDF files.
The developer of the project is Claes Spett, a security researcher at SecRecon. He provides the software via Google Drive and advises everyone who downloads it on responsible use. Of course, this will not prevent malicious use of the software.
Another use of the utility could be for research, awareness and empowerment of staff on security issues in a company. Since it exploits PDF files, it is suitable for phishing attacks and social engineering tests, for staff training. PDF Exploit Generator can become a good training tool, but also very destructive in the wrong hands.

