Adobe, Mozilla Users At Risk To Remote Code Execution Flaws
Software maker Adobe Systems has certainly had its share of vulnerabilities recently. This week a security researcher added to the company's pain when he announced a vulnerability in Adobe Download Manager that allows remote attacks. Mozilla Firefox users are also at-risk to attacks against an unpatched flaw in that browser.
February 20, 2010
Software maker Adobe Systems has certainly had its share of vulnerabilities recently. This week a security researcher added to the company's pain when he announced a vulnerability in Adobe Download Manager that allows remote attacks. Mozilla Firefox users are also at-risk to attacks against an unpatched flaw in that browser.Israeli security researcher Aviv Raff says he discovered a flaw in Adobe's web site that enables malicious attackers to abuse Adobe Download Manager to force the automatic download of Adobe applications. Theoretically, the attackers could force the installation of a vulnerable Adobe product on a target's system, and then use that application to exploit the end user. Considering the wave of Adobe software vulnerabilities in Adobe Reader and Adobe Flash recently, such a scenario is well within reason.
As Raff explains it on his blog, an attacker merely needs to entice a user to click on a link to initiatate the download, or embed the link within an iFrame on a website.
David Lenoe of the Adobe Product Security Incident Response Team says the company is working with Raff and the vendor Adobe's third part vendor for the component of their software to resolve the issue.
Meanwhile, users of Mozilla Firefox are vulnerable to remote code exploitation, where an attacker can inject code of their choice onto a victim's system.
No other details have been released on this particular flaw, but security firm Secunia has ranked the vulnerability as "highly critical."
No fix or workaround information is currently available, other than the advice to avoid untrusted links and web sites.
Read more about:
2010About the Author(s)
You May Also Like
Why Effective Asset Management is Critical to Enterprise Cybersecurity
May 21, 2024Finding Your Way on the Path to Zero Trust
May 22, 2024Extending Access Management: Securing Access for all Identities, Devices, and Applications
June 4, 2024Assessing Software Supply Chain Risk
June 6, 2024Preventing Attackers From Wandering Through Your Enterprise Infrastructure
June 19, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024