Vulnerabilities in Adobe Reader, Acrobat are already being exploited in the wild
While Microsoft kept security managers busy with one of its largest Patch Tuesday bulletins ever, Adobe was quietly fixing its own flaws, which may already be known to the hacking community.
Critical vulnerabilities have been identified in versions 9.1.3, 8.1.6, and 7.1.3 of Adobe Reader and Acrobat, according to a security update issued today by Adobe.
"These vulnerabilities could cause the application to crash, and could potentially allow an attacker to take control of the affected system," the company said.
Among other flaws, Adobe's patch resolves a heap overflow vulnerability that could lead to code execution (CVE-2009-3459), the company said. There are reports this issue is being exploited in the wild via limited, targeted attacks, Adobe acknowledged.
Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.
Read more about:
2009About the Author(s)
You May Also Like
Beyond Spam Filters and Firewalls: Preventing Business Email Compromises in the Modern Enterprise
April 30, 2024Key Findings from the State of AppSec Report 2024
May 7, 2024Is AI Identifying Threats to Your Network?
May 14, 2024Where and Why Threat Intelligence Makes Sense for Your Enterprise Security Strategy
May 15, 2024Safeguarding Political Campaigns: Defending Against Mass Phishing Attacks
May 16, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024