24 Feb 2010
Adobe has released a security update fixing a critical flaw in its Download Manager software that could let attackers download and install unauthorised software onto a user's system.
The issue applies to any instance of the software downloaded before today, but will not apply to any new versions, the firm said.
"Adobe Download Manager is designed to remove itself from the computer after use at the next computer restart. However, Adobe recommends users verify that a potentially vulnerable version of the Adobe Download Manager is no longer installed on their machine," said the security bulletin.
Adobe credited security researcher Aviv Raff for bringing the flaw to the company's attention.
"Recently, I found a design flaw on Adobe's web site which allows the abuse of the Adobe Download Manager to force the automatic installation of Adobe products, as well as other software products (e.g. Google Toolbar)," Raff said in a blog post.
"Instead of admitting that this design flaw is indeed a problem which can be abused by malicious attackers, Adobe decided to downplay this issue."
Adobe urged users to see whether the C:\Program Files\NOS\ folder and its contents (NOS files) are present on their system. If they are, the firm recommends running the 'services.msc' prompt and making sure that 'getPlus(R) Helper' is not in the list of services. If it is, it should be removed.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Sneak peek at the forthcoming glass-based machine
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Our client, a leading IT services and consulting organization...
Midweight PHP Developer // LAMP // HTML // CSS...
My client a leading global financial company is seeking...
QA Test Analyst – Selenium RC – Java – Automation – Bug...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?