Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

December 20th, 2012, 10:30 GMT · By

BLOG

US-CERT Warns About 2-Year-Old Vulnerability in Adobe Shockwave Player

SHARE:

Adjust text size:


US-CERT warns of serious vulnerability in Adobe Shockwave Player Enlarge picture - US-CERT warns of serious vulnerability in Adobe Shockwave Player
The United States Computer Emergency Readiness Team (US-CERT) has issued an advisory to warn users about a vulnerability – affecting Adobe Shockwave Player Player 11.6.8.638 and earlier versions for Windows and Mac  which could be leveraged by cybercriminals to execute arbitrary code on the target system.

Apparently, the full version of Shockwave player 11.6.8.638 comes with Flash 10.2.159.1. This Flash version is the component that contains the security holes.

According to experts, an attacker can execute arbitrary code with the privileges of the victim, simply by convincing them to view maliciously crafter Shockwave content.

The US-CERT reveals that, despite the fact that Adobe has been aware of the issue for over two years (since October 2010), the hole still hasn’t been fixed and, currently, there are no known practical mitigations.

The agency advises users to apply a series of workarounds, including disabling Shockwave Player in their browsers, and the use of Microsoft’s EMET and the Data Execution Prevention (DEP) mechanisms available in newer versions of the Windows operating system.

Adobe representatives have told Brian Krebs that they’ve been working on addressing this issue in the next major update, which is scheduled to be released in February 2013.

TELL US WHAT YOU THINK:

1,140 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Drupal 7.18 and 6.28 Released to Address Security Vulnerabilities

Post Inject Vulnerability Uncovered in SonicWall SonicOS 5.8.1.8

Samsung Exynos Kernel Exploit Highlights the Risks of the BYODTrend

WordPress Pingback Vulnerability Can Be Abused for DDOS Attacks

Sentenced Hacker “Cosmo the God” Said to Be Behind WBC Twitter Hack

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM