Emergency Adobe Flash Player patch coming today
Summary: Less than a week after warning that hackers were embedding malicious Flash Player files (.swf) into Microsoft Word documents to launch targeted malware attacks, Adobe plans to release an emergency Flash Player patch today to fix the underlying problem.
Less than a week after warning that hackers were embedding malicious Flash Player files (.swf) into Microsoft Word documents to launch targeted malware attacks, Adobe plans to release an emergency Flash Player patch today to fix the underlying problem.
The patch will fix a "critical" vulnerability in Flash Player 10.2.153.1 and earlier versions for Windows, Mac OS X Linux and Solaris.
According to this Secunia advisory, the flaw allows a hacker to completely hijack a vulnerable Windows computer:
A vulnerability has been reported in Adobe Flash Player, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an error when parsing ActionScript that adds a custom function to the prototype of a predefined class. This results in incorrect interpretation of an object (i.e. object type confusion) when calling the custom function, which causes an invalid pointer to be dereferenced.
Secunia has posted a technical analysis of the flaw as well.
Adobe has confirmed that the vulnerability (CVE-2011-0611) could cause a crash and potentially allow an attacker to take control of the affected system.
There are reports that this vulnerability is being exploited in the wild in targeted attacks via a malicious Web page or a Flash (.swf) file embedded in a Microsoft Word (.doc) or Microsoft Excel (.xls) file delivered as an email attachment, targeting the Windows platform. At this time, Adobe is not aware of any attacks via PDF targeting Adobe Reader and Acrobat. Adobe Reader X Protected Mode mitigations would prevent an exploit of this kind from executing.
A patch for Google Chrome users is already available in Chrome version 10.0.648.205.
Adobe plans to fix the vulnerability in Adobe Acrobat and Adobe Reader at a later date.
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback
RE: Emergency Adobe Flash Player patch coming today
RE: Emergency Adobe Flash Player patch coming today
I as well would like to know for my Windows side as I run the beta as well. Does the vulnerability exist in the beta or is it safe? If it wasn't for certain sites to rely on flash for their apps such as some banks I would just do without Flash same goes for YouTube. Also with Google trying to put an end to H.264 which doesn't require a flash player and can be natively put in HTML5 they are as well forcing the users to run Flash for Google's stupid Ads on YouTube. The irony is with AdBlock Plus and the right subscriptions I see no ads. Also with the converted TPL's most of that is gone from IE9 as well. I miss the days of the early internet when you got the information you needed without being bombarded with stupid crap nor blinky flashy crap that could give people seizures when they are just trying to read the news or get information. What ever happened to the information super highway? Seems like a lot of pot holes and other things are now common practice.
Very Happy
RE: Emergency Adobe Flash Player patch coming today
I hear you on that one. I'm no fan of flash ads or even Google's text based ads as I never care for what they are or what they say. On the other hand there are a lot of web sites that rely on flash to run their apps such as some banks and so forth. I wish they would move away from Flash and stick to a new standard. No need for stupid plugins or how Oracle and Adobe bundle crap like toolbars and McCrappy AV with their offerings. I'm all for sites to get revenue to keep up and running but I don't click ads nor have I ever cared for them. If I want something I will do research or just go out and get it. Ads to me are irrelevant as I'm sure to most others as well, I don't know where they get their revenue from... Maybe old or not so bright people who know no better.
RE: Emergency Adobe Flash Player patch coming today
I wouldn't do my online banking through a Flash-based website. What banks use it?
What will make Flash better - fixing or rewriting it from the scratch? (NT)
RE: Emergency Adobe Flash Player patch coming today
The more complex any given system becomes, the more difficult it is to secure such a system.
In my opinion - you-can-do-everything is not a player.
deleted by user
double post
Message has been deleted.
Who's John Gruber?
RE: Emergency Adobe Flash Player patch coming today
http://img854.imageshack.us/i/systemsecurewithsecunia.jpg/
Oh, yes. I kept my system up-to-date.
Message has been deleted.
RE: Emergency Adobe Flash Player patch coming today
RE: Emergency Adobe Flash Player patch coming today
<a href="http://www.yuregininsesi.com" title="seslichat">sesli chat</a> <a href="http://www.yuregininsesi.com" title="seslisohbet">sesli sohbet</a>