EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsMedium

A user reports receiving an email with an attached PDF document. Upon opening the PDF, nothing visible happens, but the user's antivirus software immediately flags a 'Heap Spray' exploit attempt. Which type of malware attack is this indicative of?

  1. ADrive-by Download
  2. BZero-day Exploit
  3. CBuffer Overflow
  4. DClient-side Exploit
Show answer & explanation

Correct answer: D. Client-side Exploit

A 'Heap Spray' exploit attempt originating from opening a PDF document on the user's machine is a classic example of a client-side exploit. These exploits target vulnerabilities in applications running on the user's system (the 'client'), such as PDF readers, web browsers, or office suites, rather than vulnerabilities in a server.

Why the other options are wrong

  • A. A drive-by download occurs when malware is downloaded without user interaction, often just by visiting a compromised website, not necessarily by opening a specific document.
  • B. A zero-day exploit refers to a vulnerability that is unknown to the vendor, but it describes the nature of the vulnerability, not the attack vector or type of attack itself. This attack *could* be a zero-day, but 'client-side exploit' better describes the mechanism.
  • C. Buffer overflow is a type of vulnerability that can be exploited, but it's not the overarching attack category. Heap spray is a technique used in conjunction with buffer overflows or other memory corruption vulnerabilities, often in a client-side context.

Client-side Exploit

An attack that targets vulnerabilities in software applications running on a user's computer (the 'client'), such as web browsers, email clients, or document viewers, to gain control or install malware.

  • Relies on user interaction (e.g., opening a malicious file, visiting a compromised website).
  • Targets common applications like PDF readers, browsers, office suites.
  • Often uses techniques like heap spray or remote code execution.

Memory trick: Client-side attacks hit the user's app, not the server's back.

More Malware Threats questions