Adobe Warns of Flash, PDF Zero Day Attack

Adobe issued an alert late Friday night to warn about zero-day attacks
against an unpatched vulnerability in its Reader and Flash Player software
products.

The vulnerability, described as critical, affects Adobe Flash Player
10.0.45.2 and earlier versions for Windows, Macintosh, Linux and Solaris
operating systems.

It also affects the authplay.dll component that ships with Adobe Reader and
Acrobat 9.x for Windows, Macintosh and UNIX operating systems, Adobe said.

>From Adobe's 
>advisory<http://www.adobe.com/support/security/advisories/apsa10-01.html>
:

*This vulnerability (CVE-2010-1297) could cause a crash and potentially
allow an attacker to take control of the affected system. There are reports
that this vulnerability is being actively exploited in the wild against both
Adobe Flash Player, and Adobe Reader and Acrobat.*

The Flash Player 10.1 Release Candidate "does not appear to be vulnerable,"
the company said.

*Mitigation Guidance*

In the absence of a patch, Adobe recommends deleting, renaming, or removing
access to the authplay.dll file that ships with Adobe Reader and Acrobat
9.x.   This will mitigate the threat but users will experience a
non-exploitable crash or error message when opening a PDF file that contains
SWF content.

The authplay.dll that ships with Adobe Reader and Acrobat 9.x for Windows is
typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll
for Adobe Reader or C:\Program Files\Adobe\Acrobat 9.0\Acrobat\authplay.dll
for Acrobat.

Adobe Reader and Acrobat 8.x are confirmed not vulnerable.

Adobe security chief Brad Arkin said the company received the first
malicious sample around 10:30 AM on Friday.  There is no information on when
a patch will be available.



Source:
http://threatpost.com/en_us/blogs/adobe-warns-flash-pdf-zero-day-attack-060410?utm_source=Newsletter_060710&utm_medium=Email+Marketing&utm_campaign=Newsletter&CID
=



Regards,

0xN41K

-- 
You received this message because you are subscribed to the Google Groups 
"nforceit" group.
To post to this group, send an email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/nforceit?hl=en-GB.

Reply via email to