Switchfast Blog: The Future of IT
Zero-Day Flaw Affecting Adobe Flash, Reader
Monday, June 07, 2010 by Matt Hymel
Late Friday, Adobe released a security bulletin notifying users of a
critical vulnerability found in Adobe Flash Player and Adobe Reader
and Acrobat. Straight from the advisory bulletin, "this
vulnerability could cause a crash and potentially allow an attacker
to take control of the affected system. There are reports that this
vulnerability is being actively exploited in the wild."
The affected software includes versions from all platforms,
including Windows, Macintosh, Linux, and Solaris operating systems.
The recent Flash Player 10.1 Release Candidate appears to have
avoided the vulnerability, as well as Adobe Reader and Acrobat 8.x
(only version 9.x appears vulnerable so far).
According to an article over at Computerworld.com, Secunia, a
Danish bug tracker, rated the threat as "extremely critical." This
is the highest ranking for its five-step scoring process.
U.S. Computer Emergency Readiness Team (US-CERT) which is a
branch from the federal Department of Homeland Security also posted
a warning of the vulnerability on their website.
The vulnerability is not only within Flash, but found within the
"authplay.dll" file packaged with every Windows copy of Reader and
Acrobat. This file interpreter handles Flash content embedded
within PDF files.
A quick post from TheRegister.com points out that
these bugs are the "latest in a series of security pratfalls to
befall Adobe software," pointing out that this latest flaw can be
blamed on the "support of exotic files and formats within PDF
files, a problem that has cropped up in the past."
Also, this latest security mishap comes on the heels of Adobe's
director of security and privacy, Brad Arkin, speaking out to
improve development practices as the company seems to be in a
"security spotlight".
There is no timetable for a patch to ship - follow our Twitter account for more details regarding
fixes.
Until Next Time -
Matthew Hymel
Switchfast Technologies
Chicago IT Support &
Consulting
Rochester
IT Support & Consulting
Leave comment: