Feeds

Adobe muzzles TWO zero-day wild things with emergency Flash patches

Critical block for active Win and Mac attacks

The Power of One eBook: Top reasons to choose HP BladeSystem

Updated Adobe published a critical Flash Player update on Thursday that fixes not just one but two zero-day flaws, both under active attack by hackers.

Both Windows and Mac users are in the firing line. One of the vulnerabilities (CVE-2013-0633) is being harnessed in targeted attacks designed to trick marks into opening a Microsoft Word document email attachment that contains malicious Flash (SWF) content. The exploit targets the ActiveX version of Flash Player on Windows.

The second vulnerability (CVE-2013-0634) is designed to attack Safari and Firefox browser users on Macs. The assault involves malicious Flash (SWF) content delivered by a drive-by download-style attack from booby-trapped websites. The second vulnerability is also being abused to hack Windows machines using malicious Word attachments, again featuring malicious Flash content.

Users of Adobe Flash Player 11.5.502.146 and earlier for Windows and Macintosh should update to Adobe Flash Player 11.5.502.149, as explained in an emergency bulletin by Adobe. The updates also cover Flash on Linux and for Android smartphones - although the need to update on those instances is not as pressing.

Users of Google Chrome and Internet Explorer 10 will get built-in Flash components updates automatically from Google and Microsoft, respectively.

Early indications don't shed much light on who is being attacked in the wild but the seriousness of the flaws and the potential for harm is beyond doubt. Exploitation of flaws in Adobe Flash, along with Java flaws, browser vulnerabilities and PDF exploits are among the most prevalent hacking tactics and have been for at least a couple of years. It's worth going through Adobe's irksome update process to apply these fixes. Patch now or risk getting pwned later. ®

Update: Exploit used to target aerospace industry

Security tools firm AlienVault reports that Microsoft Office files containing the exploit have cropped up in an spearphishing campaign targeting businesses in the aerospace industry, among others. One of these files uses an 2013 IEEE Aerospace Conference schedule as a lure.

Another sample containing the exploit is themed around information about an online payroll system that's primarily used in the US.

In both cases the booby-trapped Word .doc files contain an embedded flash file with no compression or obfuscation.

Designing a Defense for Mobile Applications

More from The Register

next story
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
Four fake Google haxbots hit YOUR WEBSITE every day
Goog the perfect ruse to slip into SEO orfice
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.