WinRT PDF is the default PDF reader for Windows 10. However, this particular app puts Edge at risk in a similar way that Flash, Java, and Acrobat apps have exposed internet users in recent years.
The Windows Runtime (WinRT) PDF Renderer library, or simply WinRT PDF, is a powerful component built into recent versions of the Windows operating system that allows developers to easily integrate a PDF viewing feature into their applications.
The library is used by many applications distributed through the Windows Store. It is included as the default PDF Reader application in Windows 8 and 8.1, as well as in the Edge browser in Windows 10.
Mark Vincent Yason, a security researcher at IBM's X-Force Advanced Research team, discovered that WinRT PDF can be exploited in drive-by attacks in the same way that attackers used Flash or Java.
WinRT PDF, as mentioned above, is the PDF reader that Edge uses by default.
So any PDF file embedded within a web page will open within the library. A clever attacker could exploit WinRT PDF with a PDF file that could be opened secretly, using an iframe off-screen with CSS.
The malicious code will exploit the WinRT PDF vulnerability in the same way that exploit kits like Angler or Neutrino use to deliver malicious Flash, Java, or Silverlight payloads.
Mr. Yason will present a more in-depth presentation of this attack scenario at the RSA Security conference in San Francisco.
