Skip to main content

Adobe Flash under fire with another zero-day exploit

Less than a week after warning users about a zero-day exploit in its PDF software, Adobe found another zero-day exploit in Flash. Adobe said hackers are already taking advantage of a critical flow in the current version of Flash to attack Windows PCs to “cause a crash and potentially allow an attacker to take control.”

Despite Adobe’s claims that the attacks are “limited” and “targeted” only at Windows users, the flaw is pretty far-reaching. All editions of Flash 9 and 10, including those for Windows, Mac, Linux, Solaris, and Google’s Android mobile operating system, and earlier versions, are affected. It’s also present in Adobe Reader and Acrobat, as well, since both programs include code to run Flash embedded in PDF documents. There are no reports of hackers exploiting the bug in PDF applications at this time, according to the company.

Technical details of the exploit were not disclosed, but a fix is already in the works. The company will release a patch for Flash in two weeks, or the week of Sept. 27; Acrobat and Reader will have to wait an extra week longer, or the week of Oct. 4, for a patch. Instead of waiting for the normal update on Oct. 12, these patches will be pushed out as an “out of band” security update.

Flash and Reader are Adobe’s two most prominent applications and frequently under attack by hackers. There have been three emergency patches for Reader over the past three months. The latest zero-day exploit reported earlier this month involved JavaScript. For users waiting for the patch, Microsoft announced Sept. 10 that Microsoft’s Enhanced Mitigation Experience Toolkit 2.0 offers some protection against ongoing attacks.

Flash was updated via another emergency patch in June to close a zero-day hole.

All this is just enough to make us wonder again if Steve Jobs is onto something with his adamant refusal to allow Flash on the iPhone and iPad.

Fahmida Y. Rashid
Former Digital Trends Contributor
How to alphabetize lists in Microsoft Word
Microsoft word document.

Microsoft Word is a powerful word processing application that's capable of creating complex and compelling documents. It can also perform very simple but useful tasks, like alphabetizing a list.

Here's how to alphabetize lists in Microsoft Word.

Read more
How to change margins in Google Docs
Laptop Working from Home

You may find that Google Docs has a UI that is almost too clean. It can be difficult to find basic things you're used to, such as margin settings. Don't worry, though, you can change margins in Google Docs just like with any other word processor through a couple of different means.

Read more
Snag a year’s access to Norton’s ‘Secure VPN’ while it’s 75% off
A close-up of a computer monitor displaying a generic VPN.

For one of the best VPN deals today, check out Stack Social which currently has Norton Secure VPN available for just $20 for a one-year subscription instead of the usual price of $80. Protecting up to five devices including all your iOS and Android devices, as well as your laptop or desktop, it’s fantastic value for such strong peace of mind. If you’re in the market for a new VPN, keep reading while we explain why it’s worth buying Norton Secure VPN.

Why you should buy Norton Secure VPN
You won’t see Norton Secure VPN in our look at the best VPNs, but don’t fret as it’s still a major name in the security world featuring prominently in looks at the best antivirus software. With Norton Secure VPN, you get real-time threat protection for up to five of your devices along with online privacy.

Read more