Feeds

Critical Flash vuln under active attack, Adobe warns

Tale of two 0days

Secure remote control for conventional and virtual desktops

Adobe Systems on Monday warned of a critical vulnerability in the most recent version of its Flash Player that is being actively exploited in the wild.

The vulnerability affects Flash Player 10.1.82.76 for Windows, Macintosh, Linux, Solaris, and Android operating systems, Adobe said in an advisory. “There are reports that this vulnerability is being actively exploited in the wild against Adobe Flash Player on Windows,” the warning said, without elaborating. The latest versions of Adobe's Reader and Acrobat applications are vulnerable to the same flaw, but there's no evidence they are being exploited.

The advisory credited Steven Adair of the Shadowserver Foundation for working with Adobe's security team on the vulnerability. Members of Shadowserver weren't immediately available to respond to questions.

The disclosure means there are at least two unpatched flaws in widely used Adobe applications that are presently under attack by criminals. As reported on Wednesday, a separate flaw in Reader 9.3.4 for Windows is also being exploited in emails that try to trick recipients into clicking on an attached PDF file. Once opened, the booby-trapped document exploits a stack overflow flaw in Reader, causing machines to run malware.

While the vulnerability is in all versions of the PDF viewing software, it is being exploited only on Windows-based installations, Adobe has said.

Adobe said it plans to issue a patch for the Flash vulnerability during the week of September 27. An update fixing the Reader vulnerability is scheduled for the week of October 4. In the meantime, users should use an alternative PDF viewer such as Foxit, or if they must use Reader, use it alongside Microsoft's EMET tool.

Protecting against Flash-based exploits is going to be harder, since Flash is used by Gmail and other web-based email services, YouTube, and many other modern online technologies. The easiest way to guard against the attacks is to use the Firefox browser with the NoScript add on. It automatically blocks all Flash content and allows users to specify a list of trusted websites that are excepted. ®

Beginner's guide to SSL certificates

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Go beyond APM with real-time IT operations analytics
How IT operations teams can harness the wealth of wire data already flowing through their environment for real-time operational intelligence.
The total economic impact of Druva inSync
Examining the ROI enterprises may realize by implementing inSync, as they look to improve backup and recovery of endpoint data in a cost-effective manner.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.