Adobe patches Download Manager bug

Adobe on Tuesday pushed out an update to its Download Manager application, which manages the process of installing new versions of Reader and Acrobat, to correct a "critical" vulnerability that could allow an attacker to execute malicious code. The issue was brought to light last week in a blog post by researcher Aviv Raff, who said the flaw "allows the abuse of the Adobe Download Manager to force the automatic installation of Adobe products, as well as other software products." Raff said that even though Download Manager is designed for one-time use and then is removed upon restart, an attacker can force a victim to install a vulnerable version of Reader and Acrobat, and then launch an exploit. — DK

Sign up to our newsletters

More in News

House Intelligence Committee OKs amended version of controversial CISPA

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.

Three LulzSec members plead guilty in London

Ryan Ackroyd, 26; Jake Davis, 20; and Mustafa al-Bassam, 18, who was not named until now because of his age, all admitted their involvement in the hacktivist gang's attack spree.