ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Emergency Adobe Flash Player patch coming today

By | April 15, 2011, 10:41am PDT

Summary: Less than a week after warning that hackers were embedding malicious Flash Player files (.swf) into Microsoft Word documents to launch targeted malware attacks, Adobe plans to release an emergency Flash Player patch today to fix the underlying problem. The patch will fix a “critical” vulnerability in Flash Player 10.2.153.1 and earlier versions for Windows, Mac OS [...]

Less than a week after warning that hackers were embedding malicious Flash Player files (.swf) into Microsoft Word documents to launch targeted malware attacks, Adobe plans to release an emergency Flash Player patch today to fix the underlying problem.

The patch will fix a “critical” vulnerability in Flash Player 10.2.153.1 and earlier versions for Windows, Mac OS X Linux and Solaris.

According to this Secunia advisory, the flaw allows a hacker to completely hijack a vulnerable Windows computer:

A vulnerability has been reported in Adobe Flash Player, which can be exploited by malicious people to compromise a user’s system.

The vulnerability is caused due to an error when parsing ActionScript that adds a custom function to the prototype of a predefined class. This results in incorrect interpretation of an object (i.e. object type confusion) when calling the custom function, which causes an invalid pointer to be dereferenced.

Secunia has posted a technical analysis of the flaw as well.

Adobe has confirmed that the vulnerability (CVE-2011-0611) could cause a crash and potentially allow an attacker to take control of the affected system.

There are reports that this vulnerability is being exploited in the wild in targeted attacks via a malicious Web page or a Flash (.swf) file embedded in a Microsoft Word (.doc) or Microsoft Excel (.xls) file delivered as an email attachment, targeting the Windows platform. At this time, Adobe is not aware of any attacks via PDF targeting Adobe Reader and Acrobat. Adobe Reader X Protected Mode mitigations would prevent an exploit of this kind from executing.

A patch for Google Chrome users is already available in Chrome version 10.0.648.205.

Adobe plans to fix the vulnerability in Adobe Acrobat and Adobe Reader at a later date.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
15
Comments

Join the conversation!

Just In

RE: Emergency Adobe Flash Player patch coming today
talih Updated - 12th Aug
Great!!! thanks for sharing this information to us!

sesli chat sesli sohbet
vulnerability in Flash Player 10.2.153.1, ok but what about those of us who use flash 10,3,162,29 released in 2010? That version is more stable than the official stable (for my configuration) and it may miss the announcement because it's labeled as "beta"
0 Votes
+ -
@d.marcu
I as well would like to know for my Windows side as I run the beta as well. Does the vulnerability exist in the beta or is it safe? If it wasn't for certain sites to rely on flash for their apps such as some banks I would just do without Flash same goes for YouTube. Also with Google trying to put an end to H.264 which doesn't require a flash player and can be natively put in HTML5 they are as well forcing the users to run Flash for Google's stupid Ads on YouTube. The irony is with AdBlock Plus and the right subscriptions I see no ads. Also with the converted TPL's most of that is gone from IE9 as well. I miss the days of the early internet when you got the information you needed without being bombarded with stupid crap nor blinky flashy crap that could give people seizures when they are just trying to read the news or get information. What ever happened to the information super highway? Seems like a lot of pot holes and other things are now common practice.
0 Votes
+ -
Very Happy
Hasam1991 15th Apr 2011
I am very happy that I can't run Flash player in iOS!!!!!!! no ads for me!!
0 Votes
+ -
@Hasam1991
I hear you on that one. I'm no fan of flash ads or even Google's text based ads as I never care for what they are or what they say. On the other hand there are a lot of web sites that rely on flash to run their apps such as some banks and so forth. I wish they would move away from Flash and stick to a new standard. No need for stupid plugins or how Oracle and Adobe bundle crap like toolbars and McCrappy AV with their offerings. I'm all for sites to get revenue to keep up and running but I don't click ads nor have I ever cared for them. If I want something I will do research or just go out and get it. Ads to me are irrelevant as I'm sure to most others as well, I don't know where they get their revenue from... Maybe old or not so bright people who know no better.
0 Votes
+ -
@audidiablo

I wouldn't do my online banking through a Flash-based website. What banks use it?
0 Votes
+ -
RE: Emergency Adobe Flash Player patch coming today
Martmarty Updated - 15th Apr 2011
@Just True
making it simple, and disabling those bunch of useless features. flash is becoming like a user interface, maybe it will become an OS one day also due to its hundreds of thousands of features.
The more complex any given system becomes, the more difficult it is to secure such a system.
It should be a different way to read the outcome.
0 Votes
+ -
deleted by user
Martmarty Updated - 15th Apr 2011
NT
double post
0 Votes
+ -
Message has been deleted.
His_Shadow Updated - 18th Apr 2011
0 Votes
+ -
Who's John Gruber?
ScorpioBlue 16th Apr 2011
And should we really give a damm...
0 Votes
+ -
HA! I don't HAVE Flash, but I do use Google Chrome for that.

http://img854.imageshack.us/i/systemsecurewithsecunia.jpg/

Oh, yes. I kept my system up-to-date.
0 Votes
+ -
Message has been deleted.
wuyu663 Updated - 18th Apr 2011
0 Votes
+ -
@wuyu663 I see that you're a spammer with a spammy-looking subject and a copycat of my post. Nice try, but you can do better than that.
0 Votes
+ -
Great!!! thanks for sharing this information to us!

sesli chat sesli sohbet

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix