Yet another Adobe Flash/Reader/Acrobat 0 day

Published: 2011-04-11
Last Updated: 2011-04-11 22:33:13 UTC
by Johannes Ullrich (Version: 1)
Adobe released that a so far unpatched vulnerability has been used in recent targeted attacks.

Flash Player is vulnerable, as is the flash player component used to execute flash in Adobe Reader / Acrobat. Adobe Reader X is vulnerable bu but not exploitable. 

At this time, according to Adobe, the attack is performed using Flash files embedded in Word documents. 

Note that Flash may be embedded in other Office document formats like Excel. Adobe is not planning on an out of band patch at this point, as Adobe Reader X is not exploitable.


Johannes B. Ullrich, Ph.D.
SANS Technology Institute

