- All PDF processing such as PDF and image parsing, JavaScript execution, font rendering, and 3D rendering happens in the sandbox.
- Processes that need to perform some action outside the sandbox boundary must do so through a trusted proxy called a “broker process.”
- The sandbox creates a new distinction of two security principals: the user principal, which is the context in which the user’s logon session runs, and the PDF principal, which is the isolated process that parses and renders the PDF. This distinction is established by a trust boundary at the process level between the sandbox process and the rest of the user’s logon session and the operating system.
For more detailed information on this, Adobe has started a blog thread pertaining to this new approach, which can be found here.
Following on from this post, it appears that Adobe X is not compatible with quite a few AV Vendors, including SEP when NTP is enabled. http://kb2.adobe.com/cps/860/cpsid_86063.html#main_antivirus
ReplyDeleteLink to SEP post on Symantec connect.
ReplyDeletehttp://www.symantec.com/connect/forums/adobe-reader-x-does-not-start-protected-mode-when-ntp-enabled