Skip to main content

Adobe Flash Player has ‘critical’ security issue, won’t be addressed until next week

If you use Adobe’s Flash Player at all, tread cautiously. The company released a security advisory late yesterday revealing that a “critical vulnerability” was found in pretty much all versions of the multimedia platform as well as in Adobe Acrobat and Adobe Reader.

Affected versions include: “Adobe Flash Player 10.2.152.33 and earlier versions (Adobe Flash Player 10.2.154.18 and earlier for Chrome users) for Windows, Macintosh, Linux and Solaris operating systems, Adobe Flash Player 10.1.106.16 and earlier versions for Android, and the Authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.1) and earlier 10.x and 9.x versions of Reader and Acrobat for Windows and Macintosh operating systems.”

The vulnerability could result in a crash or potentially be exploited by a hacker to “take control of the affected system.” Worse, there are reports already that this security hole is being exploited via a Flash file (.swf) embedded in a Microsoft Excel (.xls) spreadsheet that arrives as an e-mail attachment. So for the two of you who happily download everything that comes into your mailbox, even if you don’t recognize the sender… stop. It appears that there are no similar exploits out there for Reader or Acrobat yet; Adobe notes that the Protected Mode in Reader X “would prevent an exploit of this kind from executing.”

Work on a fix is underway. Those versions of software with critical flaws — which is everything other than Reader X, since running in Protected Mode will keep you safe — are getting the most attention. Adobe expects a fix to go live “during the week of March 21, 2011.” Reader X for Windows will be addressed as well, but not until the applications quarterly security update, which is currently set for release on June 14.

Unfortunately, the question at the start of this post is a rhetorical one. If you’re on the Internet in any way, then you use Flash. Unless you’re using an Apple iDevice, of course. Somewhere in Cupertino, Steve Jobs is snickering.

Editors' Recommendations

Topics
Adam Rosenberg
Former Digital Trends Contributor
Previously, Adam worked in the games press as a freelance writer and critic for a range of outlets, including Digital Trends…
Here’s even more proof that AMD’s GPUs are in trouble
The MSI Radeon RX 7900 XTX Gaming Trio graphics card with a blue background.

AMD's upcoming plan for GPU releases have been called into question recently, and now, there's some more evidence that the company's GPUs are beginning to lose momentum.

As pointed out by Hardware Unboxed on X (formerly Twitter), MSI is slowly removing listings of AMD Radeon GPUs, specifically the 7000 series, from online retailers. Additionally, all existing products have been discontinued and the company never managed to release models for the Radeon RX 7700 XT and the 7800 XT.

Read more
You’ll never guess what this YouTuber built into a PC this time
A woman stands next to a custom-built gaming PC with a coffee maker inside.

There are gaming PCs, and there are coffee makers -- and the two do not mix. After all, who would want boiling hot coffee inside their high-end gaming desktop? The idea alone makes me shiver, but Nerdforge's Martina was brave enough to come up with this project and create a fully custom-built PC that doesn't just run, but it also makes coffee at the press of a button.

Nerdforge is a YouTube channel run by a Norwegian couple, Martina and Hansi, who dabble in all sorts of innovative crafts. And it's safe to say that this falls under that category. The project started with an idea: What if, instead of having to get up to fetch a cup of coffee, you could have a coffee maker installed right inside your PC?

Read more
Microsoft finally kills this legacy Windows app — for good this time
Skype shown on a laptop screen.

Microsoft has finally retired support on Skype for Business software, after announcing its pending deprecation during a November 2023 update.

Users will no longer have access to Skype for Business servers. They will not be able to access the XML settings for Skype for Business or have the ability to sign in for support to Skype for Business meetings, Microsoft said.

Read more