Skip to main content
← Back to Demos
PDF Abuse beginner · 15 min

PDF Launch Action Executes External Program

PDF documents can carry an OpenAction that fires automatically when the file is opened, and a Launch action can invoke an external application — a behavior attackers abuse to execute malware the moment a victim opens a document. Combined with JavaScript, these actions can chain commands that download and run payloads while the reader appears to display a harmless page. This demo uses a benign PDF whose Launch action only opens the Calculator app, reproducing the technique with zero risk. MetaDefender Deep CDR sanitizes the PDF, removing OpenAction and Launch entries along with all active content, and rebuilds a clean, fully functional document that cannot execute anything.

Attack Technique

PDF Launch action

MITRE ATT&CK

T1218.001 ↗

Platforms

linuxwindows

File Types

.pdf

MetaDefender Capabilities

Deep CDR

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---