Tue, Jul 28, 2009
Critical Exploited Vulnerability in Adobe Flash Player, Acrobat Reader
Adobe has reported that a critical vulnerability exists in current
versions of Adobe Flash Player versions 9 and 10 that allows a malicious
person to create flash media that will run commands of their choosing
on your computer when viewed. This vulnerability can be exploited in Adobe
Acrobat reader via a PDF file that contains embedded malicious flash media.
There are reports that malicious PDF files that exploit this
vulnerability are actively propagating. Adobe promises fixes on
July 30th and 31st. In the meanwhile, as a partial workaround, Adobe has
supplied instructions that temporarily disable the ability of Acrobat Reader
to display flash media embedded in a PDF file. For more information, see
http://www.adobe.com/support/security/advisories/apsa09-03.html.
To be emailed any new alerts as they appear, or to cease being emailed such alerts, send email to securityalerts-request@cs.