Monday, 07 June 2010 09:11
A critical vulnerability exists in Adobe Flash Player 10.0.45.2 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems, and the authplay.dll component that ships with Adobe Reader and Acrobat 9.x for Windows, Macintosh and UNIX operating systems. This vulnerability (CVE-2010-1297) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against both Adobe Flash Player, and Adobe Reader and Acrobat. This advisory will be updated once a schedule has been determined for releasing a fix.
Reportedly, Adobe Flash Player 10.1 Release Candidate is not vulnerable to the exploit. It is available at
http://labs.adobe.com/technologies/flashplayer10/
There is not patch yet, but the threat for Adobe Acrobat 9 and Adobe Reader 9 may be mitigated by deleteing or renaming the authplay.dll that ships with those products. The authplay.dll is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll for Adobe Reader or C:\Program Files\Adobe\Acrobat 9.0\Acrobat\authplay.dll for Acrobat.
Full details are available from Adobe at http://www.adobe.com/support/security/advisories/apsa10-01.html.