Because Adobe has some kind of serious systemic code quality issue and they get beat by exploit writers all the time. It doesn't help that their applications are so popular and widely installed that they present a juicy target. I refuse to have acrobat installed, and I'm super paranoid about where I let flash run.
If you have flash and acrobat installed and let the plugins run anytime a site requests them you're begging to be owned (and owned and owned).
That last statement might be a tad exaggerated....
I've been using Flash and Adobe/Acrobat reader for years and have yet to be "owned" through either channel, and I spend a lot of time browsing the web.
Obviously I can't speak to your situation specifically, but it is very common these days for people to have malware that was installed through an exploit that they've never detected - indeed it can be very difficult to detect a lot of modern malware without in memory analysis and skilled forensics. Signature tools and things like malware bytes are extremely hit and miss. OS X and linux are even worse off (at least with standard configurations) once something has done a remote code execution and gotten a privesc.
Poll a few people who do security work and ask them if they have acrobat or flash or the jdk installed at all, or running on pages by default. You'll hear about the same thing.
Even 5 years ago was a very different world as far as threats go.
I'd strongly suggest using an alternate PDF reader (apple, google, evince, sumatra) and using flashblock.
Without wanting to go into more details, I work a job that makes me see and analyze more Adobe vulnerabilities than anybody else outside of Adobe.
Having said that, I run both Flash and Adobe Reader (and Foxit for dubious stuff) on my normal machine. The number of 0-days exploited in the wild is not actually that big (I'd like to see stats here but I am not aware of any) and the odds of being hit by an 0-day exploit is really low. When people get owned through Adobe exploits, it is because they are not updating regularly.
I definitely agree with you that when (most) people get owned it's because they're not updating regularly - and I don't want to discount your opinion at all as clearly you're in a position to know the risks.
But (as I'm sure you know) Adobe does have 0-days quite often and can take weeks to distribute a patch. The sep 14 cve-2010-2883 drop for example was being exploited seemingly quite widely by ~sep 20, and Adobe didn't push a patch until Oct 4. That's a pretty big window to be open to a drive by iframe vuln. Also, doesn't adobe updater take 7 or 14 days between update checks? It used to, at least.
The thing about not running them at all (or on opt-in) is it also mitigates some of the danger in update lagging. It seems a majority of the time when I touch someone else's computer they have an adobe product that's out of date and being actively exploited (on the internet) - even if they appear to try to keep up to date with the patches.
I got nailed by some Whitesmoke Translator malware that seemed to re-appear every time Acrobat updated. I eventually just wiped my HD and upgraded to windows 7 which I had been putting off for a while. Nothing like a good virus to convince you it's time to wipe your HD.
An honest question - to you or anyone who basically feels the same way:
What methods do you use to determine if you're running hostile code? How often do you look? Do you check from another OS? Keep hashes of system files?
Let me expand on the theory that most malware hosts have absolutely no idea (and not just the dumb ones):
Once installed many threats actively evade AV, personal firewalls, and code signing requirements. Are you booting a livecd and checking hashes of the boot block and boot chain against previously saved values? What about the hash of your EPROMS?
I understand that sounds very paranoid - but advanced toolkits that attack the BIOS or boot loader are widely available. Are they only for juicy targets? TDL4 - an advanced threat that starts in the boot block and has used private 0-days - is engaged in the super spy thriller business of clickfraud. $10k will buy you a kit from Israel that inserts similar code into the system BIOS and is designed for non-techies to deploy.
Expecting to see increased resource usage? CPU, RAM, network speed are all far outstripping most actual application needs and the resources needed for a keylogger, afinity rewriter, ad inserter or similar are vanishingly small.
Expecting a signature hit in some security software? Authors check their own code frequently - when signatures get deployed that catch them they simply recompile and tweak until they're undetected again.
Expecting pop up ads, AV scareware, spamming activity or fraud alerts on your credit card? Some threats are like that, yes, but shrinking. Just as or more likely are threats that manipulate search results, add affiliate tags to big ticket items, slip paid SEO links into blogs, steal your banking credentials but decide you're too poor or in an inconvenient county or steal company IP/plans/etc for chinese, russian, french, korean etc. competitors - the impact of which may take years or never be identified.
Expecting unknown, suspicious or hidden processes? Hiding in plain sight is a common and effective tactic. Can you tell the difference between a game installed codec, a useful codec with legal clickstream collections installed by a torrent downloader and a codec that was installed by exploit and rewrites your network traffic? Looking at a process list how many are you positive were running last month? Can you tell if skype is loading a dll or so that it wasn't before?
Think you're an unlikely target? Odds are that's true. However, automated tools can be deployed against thousands of targets and if only one or two have something really juicy it was a worthwhile effort. Proprietary IP of almost ever type has some value to someone be it term sheets, source code, M&A data, business process, sales leads, P&L data etc. Could your SO think you're cheating? Smartphone malware sold for 3000 yaun (~$450) supposedly marketed to houswives was found running on 150,000 chinese phones - it real time tracks your location, records audio, video and pictures regularly or on demand, steals credentials and all email/im/sms traffic. If you're of no interest it's possible your next door neighbor is, or his girlfriend, or someone who gets coffee where you do.
20 years ago malware was made by hobbyists. 10 years ago malware was made by small independent businessmen and specialty concerns. 5 years ago malware was made by organized crime, corporate espionage and intelligence agencies. Today malware is made by private organizations with hundreds of employees and traditional office space, teams supporting major M&A lawyers, the FBI to execute wiretapping warrants, defense contractors, ad networks, energy companies, virtual currency resellers, intelligence services conducting broad surveillance on foreign populations and security services conducting broad surveillance on their own citizenry.
One reason you don't hear a lot about it is there are very few practical solutions out there to be implemented. Microsoft, Google, Apple, Oracle and Intel are all making inroads to various degrees but practically it is decidely a losing game so far. For the time being their profit margins depend on people not getting scared away. Law enforcement and Intelligence services that might have warned against such threats in another era are by in large too busy exploiting them.
I fully understand that this all sounds very tinfoil hat and extremist. All the examples given are real and happening to very real people every day. The threat model has radically changed - it may just take another 3-5 years for everyone to understand the new rules.
This might be a paranoid way of looking at it, but certainly true. Stuxnet was and is deployed on thousands of computers for several years until they found it. I wonder how much else is just sitting there undetected.
Make sure the user account that you run flash and adobe reader under is not privileged. I hosed my account once on a bad pdf, but it didn't get past the one user account.
be aware that pretty much anything doing a remote code execution follows it up with local privilege escalation exploits - which are rather common and frequently don't get top priority for fixes.
If you have flash and acrobat installed and let the plugins run anytime a site requests them you're begging to be owned (and owned and owned).