Chicago IT Support and Consulting


information technology blog

Switchfast Blog: The Future of IT

Zero-Day Flaw Affecting Adobe Flash, Reader

Monday, June 07, 2010 by Matt Hymel

Late Friday, Adobe released a security bulletin notifying users of a critical vulnerability found in Adobe Flash Player and Adobe Reader and Acrobat. Straight from the advisory bulletin, "this vulnerability could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild."

The affected software includes versions from all platforms, including Windows, Macintosh, Linux, and Solaris operating systems. The recent Flash Player 10.1 Release Candidate appears to have avoided the vulnerability, as well as Adobe Reader and Acrobat 8.x (only version 9.x appears vulnerable so far).

According to an article over at Computerworld.com, Secunia, a Danish bug tracker, rated the threat as "extremely critical." This is the highest ranking for its five-step scoring process.

U.S. Computer Emergency Readiness Team (US-CERT) which is a branch from the federal Department of Homeland Security also posted a warning of the vulnerability on their website.

The vulnerability is not only within Flash, but found within the "authplay.dll" file packaged with every Windows copy of Reader and Acrobat. This file interpreter handles Flash content embedded within PDF files.

A quick post from TheRegister.com points out that these bugs are the "latest in a series of security pratfalls to befall Adobe software," pointing out that this latest flaw can be blamed on the "support of exotic files and formats within PDF files, a problem that has cropped up in the past."

Also, this latest security mishap comes on the heels of Adobe's director of security and privacy, Brad Arkin, speaking out to improve development practices as the company seems to be in a "security spotlight".

There is no timetable for a patch to ship - follow our Twitter account for more details regarding fixes.

 

Until Next Time -

Matthew Hymel

 

Switchfast Technologies
Chicago IT Support & Consulting
Rochester IT Support & Consulting

submit to reddit
0 comment(s) for “Zero-Day Flaw Affecting Adobe Flash, Reader”

    Leave comment:

    Name:  
    Email:  
    Website:
    Comment:  




    Archives