Adobe patches Flash Player hole exploited in the wild
Posted on 07 May 2012.
Adobe has released a security update for Flash Player for Windows, Macintosh, Linux and Android that address the object confusion vulnerability (CVE-2012-0779) that is currently being used in the wild.

The attackers target only Windows users so far, but Adobe advises all users to update their software.

According to Adobe and to Symantec researchers, the attacks take form of a variety of spam emails containing specially crafted malicious attachments.

"For the exploit to successfully work, the malicious attachments need to be opened on a computer with a vulnerable version of Adobe Flash Player," Symantec researchers reveal.

"The malicious documents contain an embedded reference to a malicious Flash file hosted on a remote server. When the Flash file is acquired and opened, it sprays the heap with shellcode and triggers the CVE-2012-0779 exploit. Once the shellcode gains control, it looks for the payload in the original document, decrypts it, drops it to disk, and executes it."

Vulnerabilities in Adobe's products in general and Flash Player in particular are often exploited by cyber attackers, so the company introduced silent automatic updating for Flash Player on Windows in March, and is working on releasing a stable Flash Player for Mac with the feature soon.






Spotlight

How to talk infosec with kids

Posted on 17 September 2014.  |  It's never too early to talk infosec with kids: you simply need the right story. In fact, as cyber professionals itís our duty to teach ALL the kids in our life about technology. If we are to make an impact, we must remember that children needed to be taught about technology on their terms.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Fri, Sep 19th
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //