Adobe readies Flash fix for Thursday

Share this article:

Adobe plans to rush out a fix for a Flash Player zero-day vulnerability by Thursday, and users will have to wait until June 29 to receive a patch for the same flaw in Reader and Acrobat.

The bug, which could cause a crash or allow an attacker to take control of an affected system, is present in the latest version of Flash (10.0.45.2) and earlier for Windows, Macintosh, Linux and Solaris operating systems, Adobe said in a security advisory Friday. Adobe did not say when it plans to patch the vulnerability, first reported on Friday, in Solaris.

The bug also affects the authplay.dll component of Adobe Reader and Acrobat 9 for Windows, Macintosh and UNIX operating systems. The cause of the vulnerability was unspecified.

“There are reports that this vulnerability is being actively exploited in the wild against both Adobe Flash Player, and Adobe Reader and Acrobat,” the company said in its advisory.

The flaw is rated “extremely critical,” or a five out of five, by vulnerability tracking firm Secunia.

The Flash Player 10.1 release candidate is confirmed as not vulnerable, as are Reader and Acrobat version 8.

To avoid a possible exploit, users also can consider disabling the Flash ActiveX control or installing a Flash blocker add-on, experts said. To avoid an attack in Reader or Acrobat, users can run an alternative PDF renderer.

Share this article:
You must be a registered member of SC Magazine to post a comment.
close

Next Article in News

Sign up to our newsletters

TOP COMMENTS

More in News

Florida Supreme Court rules warrants a must for real-time cell location tracking

Florida Supreme Court rules warrants a must for ...

The Florida Supreme Court put the kibosh on warrantless real-time tracking using location data obtained from cell phone providers.

Modular malware for OS X includes backdoor, keylogger components

Modular malware for OS X includes backdoor, keylogger ...

The modular malware was named "Ventir," by researchers at Kaspersky.

Fake Dropbox login page nabs credentials, is hosted on Dropbox

Fake Dropbox login page nabs credentials, is hosted ...

Symantec researchers received a phishing email linking recipients to a fake Dropbox login page that is hosted on Dropbox's user content domain and served over SSL.