25 Jun 2008
Adobe has issued fixes for a critical vulnerability being exploited by malware writers.
The flaw affects the firm's Acrobat and Adobe Reader applications on Mac OS and Windows.
Adobe recommends that users of both platforms install the security update immediately.
The vulnerability could allow an attacker to gain control of the user's system by way of malformed JavaScript code.
When exploited, the vulnerability leads to an application crash which leaves the user liable to remote control of the system and code execution from the attacker.
Such remote code execution flaws are a favourite method for covertly installing malware and are often regarded as the highest risks among software vulnerabilities.
Adobe has classified the flaw as 'critical', the highest of its four security alert levels. The company noted that there is a heightened risk as the flaw is already being used by attackers to spread malware in the wild.
Sans security researcher Jason Lam echoed Adobe's sense of urgency, recommending that users install the update as soon as possible.
"This is likely to appear in a malware spreading website near you soon given the track record of the botnet operators," he wrote.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
My client is a well established, non profit organisation;...
PHP Web Developer – £30,000 - £35,000 PHP, MySQL, HTML...
HEAD OF DIGITAL - London - £80-95K + Excellent Bens...
Agile C# Developer - (North London) £55,000 - £65,000...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?