Skip to main content

Adobe Flash Flaw Could Give Attackers Full Control

Less than a week after security researchers warned of a vulnerability in two Adobe programs that could allow hackers to compromise a PC comes yet another critical exploit that could hijack your desktop. This time, attackers have targeted Adobe's Flash animation software. According to iDefense Labs, remote exploitation of the vulnerability in the Flash player could allow an attacker to execute arbitrary code with full user privileges. That means anything you could do with your PC, the attacker could, too. "To exploit this vulnerability, a targeted user must load a malicious Shockwave Flash file created by an attacker," iDefense Labs said. "An attacker typically accomplishes this via social engineering or injecting content into a compromised, trusted site." Adobe's Black Eye Adobe already has a black eye because of a zero-day vulnerability in Acrobat Reader that has attracted a lot of attention in the press and the security community, according to Andrew Storms, director of security operations for nCircle. The network security and compliance automation firm works with companies like Safeway, U.S. Cellular, and Archer Daniels Midland. "Some people are asking why is it taking Adobe so long to release a patch for the Acrobat bug when third-party companies have already released mitigation steps and a few have even released their own Acrobat patches," Storms said. "Meanwhile, apart from a simple security notice on its Web site, Adobe has been conspicuous by their silence." The optimistic view is that Adobe has been busy working on a Flash update and ensuring a high level of quality in its Acrobat patch. Storms said we have little choice but to take the optimistic view because anything else would further degrade Adobe's reputation with an information-security community already surprised by its lack of response. "At this point, Adobe needs to do two things in a hurry," Storms said. "First, they need to provide mitigation advice for both the known Acrobat zero-day vulnerability and this new Flash advisory. Second, they need to begin an advance notification program so enterprises can plan for Adobe patches." Adobe's Response Adobe wasn't immediately available for comment, but Tuesday afternoon confirmed the vulnerability in its Flash software on all platforms. The vulnerability is in Adobe Flash Player 10.0.12.36 and earlier versions. Adobe rates the vulnerability as critical. Adobe recommended users update to the most current version of Flash Player for their platform. For users who cannot update to Flash Player 10, Adobe has developed a patched version of two earlier versions that are available for download. However, there is still no update on the Adobe Reader and Acrobat flaws. Adobe said in an earlier security advisory that it will make an update for Adobe Reader 9 and Acrobat 9 by March 11. That is still two weeks away. Meanwhile, attackers are actively exploiting the flaw. Adobe's only advice: Disabling JavaScript in Reader and Acrobat may protect users. "Disabling JavaScript provides protection against currently known attacks," Adobe said in its Feb. 19 security advisory. "However, the vulnerability is not in the scripting engine and, therefore, disabling JavaScript does not eliminate all risk."

Comments

Popular posts from this blog

The security log on this system is full. Only administrators can log on to fix the problem.

The security log on this system is full. Only administrators can log on to fix the problem. To resolve this issue, use an account that is a member of the Administrators group to log on to the computer. Then, follow these steps to specify that Security log events can be overwritten: 1. Click Start, point to All Programs, point to Administrative Tools, and then click Event Viewer. 2. Right-click Security, and then click Properties. 3. In the Log Size area of the Security Properties window, click the Overwrite events as needed option under When maximum log size is reached. 4. Click OK. 5. Close Event Viewer.

CWBLM0011 - An Internal License Management Error Occurred.

CWBLM0011 - An Internal License Management Error Occurred. RESA II started recieving error messages when users would sign on with client access express running on Windows 2000, the first client would connect but the second would get a license code error that said internal licensing error, here is a description from IBM's website, "Windows NT/2000 Restricted Users (User Group) attempting to start a 5250 terminal emulation session running Client Access Express (5769XE1) V5R1M0 receive a CWBLM0011 error message. This error does not occur when logged on to the PC as the Windows Administrator. The error appears more frequently when the users attempt to start multiple Client Access sessions." It appears to happen because the user doesn't have permissions to update some registry keys that client access likes to update occasionally, so this error message can happen at any time and doesn't appear to have any rhyme or reason. In RESA II's case, Tim believed it was ca...