Hackers exploit Flash zero-day, Adobe confirms
Plans to patch Flash, Reader next week, but cites Reader X's sandbox as reason why it won't update newest version
Computerworld - Adobe today confirmed that attackers are exploiting an unpatched bug in Flash Player using Microsoft Excel documents.
The company will patch Flash next week and will also update Adobe Reader, which includes code that renders Flash content inserted in PDF files.
"They have exploits out in the wild, so they're moving pretty quickly," said Wolfgang Kandek, chief technology officer at Qualys. "That's commendable."
According to a security advisory issued Monday, attackers are exploiting the vulnerability by embedding malicious Flash files within a Microsoft Excel document sent as an e-mail attachment.
Adobe said it wasn't aware of any attacks directed at Reader or Acrobat, the popular PDF viewer and commercial PDF creator, respectively.
"This vulnerability could cause a crash and potentially allow an attacker to take control of the affected system," Adobe acknowledged in its advisory.
Brad Arkin, the company's director of product security and privacy, offered up more information in a Monday blog post. "Reports...thus far indicate the attack is targeted at a very small number of organizations and limited in scope," said Arkin.
After exploiting the Flash vulnerability, hackers are infecting systems with additional malware.
The Excel file is simply the delivery mechanism for the malicious Flash code that's exploiting the vulnerability, an Adobe spokeswoman confirmed.
"Hackers use whatever mechanism makes sense, and Excel files are generally trusted documents," said Kandek. "So [the Excel document] is just part of the social engineering element here."
Adobe will patch Flash, Reader and Acrobat next week -- the company did not specify which day, but it often releases security fixes on Tuesday -- but will not update Reader X, the newest version of the viewer that includes an anti-exploit "sandbox" designed to stymie most attacks.
Reader X's sandbox blocks the current attacks, Arkin said, and would also prevent malware from being installed if hackers switch to delivering the exploit in malicious PDFs, a frequently-used tactic with Flash exploits.
Adobe decided not to update Reader X next week because building a fix would delay the release of the Flash, Reader and Acrobat updates by a week. "Given the mitigation provided by the Adobe Reader X sandbox and the absence of attacks via PDF, we determined that an out-of-cycle update would incur unnecessary churn and patch management overhead on our users not justified by the associated risk," said Arkin.
Reader X will get a patch at the next regularly-scheduled update on June 14, Arkin added.
Users should take use the opportunity to update to Reader X, urged Kandek. "This is good example of how sandboxing provides additional hardening," he said. "At [Pwn2Own] last week, no one attempted to exploit [Google's] Chrome, for example. I think that had to do with the additional sandboxing in Chrome."
Reader X can be downloaded from Adobe's site; only the Windows version includes the sandbox technology, however.
Adobe last patched Flash and Reader Feb. 8 when it shipped fixes for 42 flaws in the two programs.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer or subscribe to Gregg's RSS feed
. His e-mail address is gkeizer@computerworld.com.
Read more about Security in Computerworld's Security Topic Center.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- IDC Security Infographic From the Era Before security to this current era of empowerment this infographic from Blue coat provides a timeline navigates the rise of...
- Key Drivers: Why CIOs Believe Empowered Users Set the Agenda for Enterprise Security Several years ago, a transformation in IT began to take place; a transformation from an IT-centric view of technology to a business-centric view...
- Security Empowers Business Every magazine article, presentation or blog about the topic seems to start the same way: trying to scare the living daylights out of...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts