Less than a week after security researchers warned of a vulnerability in two Adobe programs that could allow hackers to compromise a PC comes yet another critical exploit that could hijack your desktop.
This time, attackers have targeted Adobe’s Flash animation software. According to iDefense Labs, remote exploitation of the vulnerability in the Flash player could allow an attacker to execute arbitrary code with full user privileges. That means anything you could do with your PC, the attacker could, too.
“To exploit this vulnerability, a targeted user must load a malicious Shockwave Flash file created by an attacker,” iDefense Labs said. “An attacker typically accomplishes this via social engineering or injecting content into a compromised, trusted site.”
Adobe’s Black Eye
Adobe already has a black eye because of a zero-day vulnerability in Acrobat Reader that has attracted a lot of attention in the press and the security community, according to Andrew Storms, director of security operations for nCircle. The network security and compliance automation firm works with companies like Safeway, U.S. Cellular, and Archer Daniels Midland.
“Some people are asking why is it taking Adobe so long to release a patch for the Acrobat bug when third-party companies have already released mitigation steps and a few have even released their own Acrobat patches,” Storms said. “Meanwhile, apart from a simple security notice on its Web site, Adobe has been conspicuous by their silence.”
The optimistic view is that Adobe has been busy working on a Flash update and ensuring a high level of quality in its Acrobat patch. Storms said we have little choice but to take the optimistic view because anything else would further degrade Adobe’s reputation with an information-security community already surprised by its lack of response.
“At this point, Adobe needs to do two things in a hurry,” Storms said. “First, they need to…