Tuesday, April 12, 2011 8:20 AM cmosby

Yet another Adobe Flash/Reader/Acrobat 0 day - SANS Internet Storm Center

Yet another Adobe Flash/Reader/Acrobat 0 day
Yet another Adobe Flash/Reader/Acrobat 0 day
Share |
Published: 2011-04-11,
Last Updated: 2011-04-11 22:33:13 UTC
by Johannes Ullrich (Version: 1)
5 comment(s)

Adobe released that a so far unpatched vulnerability has been used in recent targeted attacks.

Flash Player 10.2.153.1 is vulnerable, as is the flash player component used to execute flash in Adobe Reader / Acrobat. Adobe Reader X is vulnerable bu but not exploitable.

At this time, according to Adobe, the attack is performed using Flash files embedded in Word documents.

Note that Flash may be embedded in other Office document formats like Excel. Adobe is not planning on an out of band patch at this point, as Adobe Reader X is not exploitable.

[1] http://www.adobe.com/support/security/advisories/apsa11-02.html

------
Johannes B. Ullrich, Ph.D.
SANS Technology Institute
Twitter
Keywords: adobe flash
5 comment(s)
Filed under: , , , ,

Comments

No Comments