Email this article   Print article 


Adobe Fixes Critical Security Flaws In Flash Player

By Antone Gonsalves
March 29, 2012    2:16 PM ET

Adobe Systems has released a Flash Player update that fixes two critical vulnerabilities and adds an automatic update feature.

If left unpatched, the flaws could cause a crash and allow an attacker to take control of a computer, the company said Wednesday. The update is for Flash Player versions 10 and 11 and applies to all operating systems, Windows, Mac OS X, Linux and Solaris.

Adobe has rated the patch "priority 2," which means it has yet to see malware exploiting the vulnerabilities, but recommends staying ahead of hackers by installing the update within 30 days.

Along with the patches, Adobe included an automatic update that would install the latest version of Flash Player in browsers without bothering users, who would have to first agree to turn on the feature. "We highly recommend to opt-in," Wolfgang Kandek, chief technology officer of security vendor Qualys, said in the company's blog. "Running on the latest version of Flash Player adds considerable resilience to one's setup, plus it avoids the chore of updating all of your installed browsers by hand."

The automatic update will keep Flash Player on every browser in a system up-to-date, Adobe said in the company's blog. The feature is only available on Windows XP and newer versions of the operating system. A Mac OS X version is in the works, but Adobe has not said when it would be available.

While the updater can run silently in the background, there are times when Adobe will seek permission for installation, such as when the update changes default settings in the player. "However, we could apply a zero-day patch without requiring end-user confirmation, so long as the user has agreed to receiving background updates," the company said.

The Flash Player is software used to run streaming video and audio, multimedia graphics and rich Internet applications.

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Head-To-Head: Symantec Vs. McAfee In Endpoint Protection

McAfee and Symantec are archrivals with a firm grip on the North American security market. CRN pits both vendors' endpoint security products against each other and names a winner.

The 8 Steps Behind The Massive $45M Cyber Bank Heist

More than $45 million was stolen from banks in the U.S. and 19 other countries in a scheme that law enforcement is calling an international conspiracy to drain millions from bank accounts using stolen debit cards and PIN numbers. Here's how they did it.

Name Of The Game: Top 10 States For Identity Theft

A Federal Trade Commission report provides statistics on identity theft and fraud complaints in 2012. Learn which state has the dubious distinction of having the most victims.

  More Slide Shows




Related Videos
Loading...