Feeds

Adobe patches critical Flash Player vuln under attack

One down, one to go

Next gen security for virtualised datacentres

Adobe Systems has patched a critical vulnerability in its ubiquitous Flash Player that has been under active attack for at least a week.

The company on Monday issued an update for Flash Player 10.1.82.76 and earlier versions for Windows, Macintosh, Linux, and Solaris, and Adobe Flash Player 10.1.92.10 for Android handsets. Adobe has disclosed few details about the threat other than to say it allows attackers to take complete control of computers running the application and that there are reports that it is being “actively exploited in the wild against Adobe Flash Player on Windows.”

The vulnerability also affects fully patched installations of Adobe Reader and earlier versions, for Windows, Macintosh, and Unix, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. Adobe has no reports the vulnerability in those programs is being exploited.

Monday's patch closes one of two known zero-day vulnerabilities being used to attack Adobe users. As previously reported, a highly sophisticated attack spreading by email attempts to install malware on Windows machines by tricking recipients into opening a booby-trapped PDF file. The underlying stack overflow vulnerability affects non-Windows versions of Reader as well.

Adobe has said a patch for that bug will be released the week of October 4.

As usual, Windows-based Flash users who surf the web with Firefox or another browser other than Internet Explorer will have to install the patch at least twice to be fully protected. Users are reminded to uncheck the box hawking free software such as McAfee Security Scan when updating. ®

The essential guide to IT transformation

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
prev story

Whitepapers

Best practices for enterprise data
Discussing how technology providers have innovated in order to solve new challenges, creating a new framework for enterprise data.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?