Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Advisories

September 14th, 2010, 07:18 GMT · By

Flash Zero-Day Actively Exploited in the Wild

SHARE:

Adjust text size:


Critical Flash Player exploited in the wild
Enlarge picture
Adobe warns that a critical and previously undisclosed vulnerability in Flash Player is actively being exploited in the wild to compromise computers.

"A critical vulnerability exists in Adobe Flash Player 10.1.82.76 and earlier versions for Windows, Macintosh, Linux, Solaris, and Adobe Flash Player 10.1.92.10 for Android.

"This vulnerability also affects Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh," the company writes in a newly published security advisory.

Exploiting the vulnerability can lead to a crash, which allows an attack to execute arbitrary code to compromise the system. Worse yet, the flaw was reported as a zero-day, Adobe learning about it from in-the-wild exploits.

The company is currently working on a patch and plans to release it two weeks from now, around September 27.

However, the window of exploitability will actually be longer, because this flaw also affects the Flash Player plug-in embedded into Adobe Reader.

The authplay.dll file, which enables SWF playback inside PDF, only gets updated during an Adobe Reader upgrade and the next one is scheduled for the week of October 4.

Therefore, attackers will be able to target this new zero-day bug, which is identified as CVE-2010-2884, for one week after Flash Player will be patched, by tricking users into opening rogue PDF documents with malicious SWF content embedded.

There is currently no mitigation available, but Adobe is working closely with the security industry to make detection for this exploit widely available.

As always, users are strongly advised to run a capable and up-to-date antivirus product on their computer systems at all times.

In related news, the Adobe Reader update scheduled for the beginning of next month will also address a separate PDF zero-day vulnerability that has been exploited for over a week already.

TELL US WHAT YOU THINK:

1,424 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Flash Player Vulnerable to Remote Binary Planting Attacks

Adobe's Products Lead in Number of Outdated Installations

Adobe Shockwave Player 11.5.8.612 Plugs 18 Critical Holes

Most Users Remain Vulnerable to Flash Exploits After Upgrading Flash Player

Security Fixes Available for Flash Player, AIR, ColdFusion and Flash Media Server

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM