Adobe has issued a “critical” alert that zero-day attacks are being launched on a security vulnerability in its Flash Player, PDF Reader, and Acrobat products. The alert applies to Flash Player 10.0.45.2 and earlier versions for Windows, Mac, Linux and Solaris operating systems, as well as the authplay.dll component that accompanies Adobe Reader and Acrobat 9.3.2 and earlier 9.x versions for Windows, Mac and Unix OSs.
The Security Advisory, posted by the company late Friday, noted that the 10.1 Release Candidate of the Flash Player, currently available for download, “does not appear to be vulnerable.” Similarly, Adobe Reader and Acrobat 8.x appear to be unaffected.
Possible System Control
A zero-day attack is one that has been launched before the developer, in this case Adobe, has been able to issue a patch. Adobe said the vulnerability can cause a crash and, potentially, could enable an attacker to take control of the user’s system.
The Advisory noted that “deleting, renaming, or removing access to the authplay.dll file mitigates the threat,” but it will result in a “non-exploitable crash or error message” when a PDF file with Flash content is opened.
Adobe said that the authplay.dll that comes with Adobe Reader and Acrobat 9.x for Windows is usually installed at C:Program FilesAdobeReader 9.0Readerauthplay.dll for Adobe Reader or C:Program FilesAdobeAcrobat 9.0Acrobatauthplay.dll for Acrobat.
Proves His Point
The vulnerability underscores an argument that Apple CEO Steve Jobs has been making in his battle with Adobe about using Flash on the iPad, iPhone, and iPod Touch.
Apple will not allow Flash on those devices, insisting that standards-based, emerging HTML5 technologies be used instead for the video and interactive animation for which Flash is widely employed.
In a “Thoughts on Flash” statement posted on the Apple Web site, Joba attacked Flash for being proprietary when the Web should be open, as well…