WARNING: Adobe Acrobat, Flash and Reader Zero Day Vulnerability

happygeek 0 Tallied Votes 393 Views Share

Adobe has issued a security advisory following the discovery of what it describes as a "critical vulnerability" which exists within the current versions of Flash Player (v and v) across all platforms, Windows, Macintosh and Linux operating systems, The same vulnerability can be found within the authplay.dll component that ships with Adobe Reader and Acrobat v9.x for Windows, Macintosh and UNIX operating systems and has the potential to cause a crash which could then allow an attacker to take control of the system. Well, I say potential, but that there are "reports that this vulnerability is being actively exploited in the wild via limited, targeted attacks against Adobe Reader v9 on Windows".

Adobe goes on to confirm that it is "developing a fix" which it expects to be available by way of software upgrade by the 30th of July for Flash Player v9 and v10 for Windows, Macintosh, and Linux at least. Users of Flash Player v9 and v10 for Solaris will need to wait a while longer it would seem, and a confirmed date for the security update is still pending. Adobe Reader and Acrobat v9.1.2 updates for Windows and Macintosh users should be available on 31st July, although once more the date for Adobe Reader for UNIX users is pending.

In order to mitigate the threat in the meantime, Adobe recommends deleting, renaming, or removing access to the authplay.dll file that ships with Adobe Reader and Acrobat v9.x although this will mean that users will "experience a non-exploitable crash or error message when opening a PDF that contains SWF content" which is nice. Vista users are being told to enable the User Access Control and exercise caution when browsing untrusted websites. Disabling JavaScript will not, I am led to believe, protect against the exploit on this occasion.

Depending on the product, the authplay.dll that ships with Adobe Reader and Acrobat 9.x for Windows is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll or C:\Program Files\Adobe\Acrobat 9.0]\Acrobat\authplay.dll.

The fact that the exploit is already being exploited both in the form of suspect PDF docs and drive-by download websites is truly worrying, as is the cross platform nature of the vulnerability which is just as likely to impact Firefox users as it is those with Internet Explorer.

My advice? Stop using Acrobat, Flash Player and Reader until Adobe gets its security act together once and for all. Advice that I have been giving to anyone who will listen for a few months now.

Dani AI

Generated

Thanks to for flagging this — useful heads-up. The note below does not repeat the original advisory; it gives concise, practical follow-up actions and a short incident-response checklist readers can apply now or years later.

Quick, low-disruption mitigations to reduce immediate exposure:

  • Turn on browser "click-to-play" for plugins (so Flash/other plugins do not run automatically) or block plugin content entirely. (howtogeek.com)
  • Open any untrusted PDFs in an isolated environment (a disposable VM, sandbox, or a dedicated analysis machine) rather than on your daily workstation. ()
  • Use a modern PDF reader with built-in sandbox/protected view and keep the reader and browser up to date. Where possible, use enterprise mail/web gateways to strip or flag active content in attachments.

If a machine is suspected of being exploited (short checklist):

  • Quarantine the host from the network immediately to prevent lateral movement.
  • Preserve evidence: collect memory and disk images if possible, then perform offline scans with updated AV/anti-malware tools. Follow established incident-handling procedures (identify, contain, eradicate, recover) rather than ad-hoc cleanup. (csrc.nist.gov)
  • Monitor perimeter and host IDS/IPS for known exploit traffic — vendors and CERTs published signatures and indicators when this family of Adobe/Flash issues appeared. Use those signatures to hunt for past attempts. (juniper.net)

Longer-term priorities: minimize the use of legacy plugins, run software with least privilege, automate updates, and maintain offline backups and a tested playbook for reimaging compromised hosts. For enterprise readers, plan patch testing and staged rollouts so critical fixes can be deployed quickly and safely.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.