A cross-site scripting flaw could have allowed an attacker to execute arbitrary code

Dec 1, 2011 16:03 GMT  ·  By

Adobe discovered a critical vulnerability in Flex SDK 4.5.1 and earlier versions for all the major platforms which permitted an attacker to launch a cross-site scripting attack and as a result, they launched an update.

“An important vulnerability has been identified in the Adobe Flex SDK 4.5.1 and earlier 4.x versions and 3.x versions on the Windows, Macintosh and Linux operating systems,” reveals the advisory that comes with the update.

All the users of Adobe Flex SDK 4.5.1 and earlier 4.x and 3.x variants are advised to update the software as soon as possible, but also to check if any SWF files in their applications are vulnerable. The company also released a tech note that will instruct users on how to do this.

Flex SDK is an open source framework utilized for building and maintaining expressive web applications. In combination with other tools, it can be used for developing apps for Android, BlackBerry and iOS.

Adobe Flex SDK 4.6.0 is available for download here