Almost all Windows users vulnerable to Flash zero-day attacks
Over 90% of PCs run at-risk Flash, 48% have buggy Reader, says Secunia
Computerworld - More than 9 out of every 10 Windows users are vulnerable to the Flash zero-day vulnerability that Adobe won't patch until Thursday, a Danish security company said today.
According to Secunia, 92% of the 900,000 users who have recently run the company's Personal Software Inspector (PSI) utility have Flash Player 10 on their PCs, while 31% have Flash Player 9. (The total exceeds 100% because some users have installed both.)
The most-current versions of Flash Player -- 9.0.159.0 and 10.0.22.87) -- are vulnerable to hackers conducting drive-by attacks hosted on malicious and legitimate-but-compromised sites. Antivirus vendors have reported hundreds, in some cases thousands, of sites launching drive-bys against Flash.
Secunia's PSI also pegged the installed base of the current Adobe Reader 9.1.2 and Abode Acrobat 9.1.2 at 48% and 2%, respectively. Because both include an interpreter to handle Flash content embedded in PDF files, they also can be exploited. The initial attacks, in fact, were based on rigged PDFs.
Adobe has acknowledged that Flash, Reader and Acrobat contain a critical bug. Last Wednesday, it kicked its security process into high gear, promising it would deliver patches for Flash by July 30, and fixes for Reader and Acrobat by July 31.
Until then, users have few options other than to delete, disable or rename the flawed component, "authplay.dll;" Adobe has posted terse instructions in a security bulletin, as have other organizations, including the U.S. Computer Emergency Response Team (US-CERT).
The bug at the root of the vulnerability was first logged in Adobe's bug tracking database nearly seven months ago, at the end of 2008.
PSI scans Windows systems for installed applications, then compares their version numbers to the most up-to-date editions; if they're different, it makes note, then provides a link to the patch update. "[A] PC user with vulnerabilities in his installed software, is like a house owner with open or unlocked doors," said Mikkel Winther, the manager of Secunia's PSI partner program, in an e-mail. "Maybe nobody will rob his house or compromise his system, but it is indeed possible and he hasn't secured himself against it."
Adobe has been faced with one security emergency after another this year. In mid-March, it patched several Reader vulnerabilities, then followed that with two more updates in May and June. Also last week, after Secunia noticed that Adobe continued to provide an outdated edition of Reader for download from its Web site, Adobe said it might change how its software updater worked.
Security Alert
- N.J. mayor arrested on hacking, conspiracy charges
- Untethered jailbreak for iOS 5.1.1 available for download
- Lawmakers call on DOJ to reopen investigation into Google Wi-Fi spying
- Researchers propose TLS extension to detect rogue SSL certificates
- GAO: U.S. gov't IT reform slower than claimed
- European privacy regulators want more detail on Google's policy changes
- Yahoo leaks private key, allows anyone to build Yahoo-signed Chrome extensions
- Security researcher urges IT to keep up with SAP patches
- 10 questions for Imperva CTO Amichai Shulman
- Bounty hunters find 8 Google services bugs
Read more about Security in Computerworld's Security Topic Center.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Driving Secure Enterprise File Sharing and Syncing in the Enterprise
- GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
- The Enterprise File Sharing Option
- Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
- Security Strategies to Virtualizing Internet-Facing Applications
- The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
- Cloud Security Planning Guide
- Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
- Cloud Security Vendor Round Table
- This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions... All Security White Papers
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
- FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
- BlackBerry PlayBook OS 2.0 Security Overview
- The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
- BlackBerry NFC Security Overview
- The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts