Feeds

Adobe goes out of band to fix frightful Flash flaw

Company warns of active attacks on browsers

Next gen security for virtualised datacentres

Adobe has issued an out-of-band fix to address what the company warns is an actively-targeted vulnerability in its Flash media plug-in.

The company said that the Flash 12.0.0.44 update would address a remote code execution vulnerability present in the Windows, OS X, and Linux versions of Flash Player. Users running Chrome and Internet Explorer will automatically download the update through their browsers, while other users can obtain the fix through Adobe's Download Center.

Adobe said that if targeted, the integer underflow vulnerability could cause a crash that would allow an attacker to remotely execute code and possibly take control of a targeted system.

According to the company, there have been reports of the flaw being actively targeted in the wild, prompting a high deployment priority on the Windows and OS X versions of the patch. Adobe considers the Linux update to be a lower priority at the moment.

That the company would release the update outside of its normal monthly security update schedule would indeed suggest that the flaw is a serious issue. Such out-of-band releases are fairly uncommon among companies with monthly updates, and are usually only issued when a serious vulnerability is being actively targeted.

According to security researcher and blogger Graham Cluley, the high-profile of Flash and the history of attackers targeting Adobe tools should motivate users and administrators to patch their systems quickly.

"Clearly Adobe thinks the issue is serious if it is taking the step to issue an out-of-band security patch," Cluley said in a blog post.

"In the past Adobe security flaws have been exploited widely by online criminals to infect unprotected computers, so internet users would be wise to take the threat seriously and patch their systems as appropriate." ®

The essential guide to IT transformation

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
prev story

Whitepapers

Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up distributed data
Eliminating the redundant use of bandwidth and storage capacity and application consolidation in the modern data center.
The essential guide to IT transformation
ServiceNow discusses three IT transformations that can help CIOs automate IT services to transform IT and the enterprise
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.