Adobe has published a security advisory in response to a critical flaw found in Flash Player. The vulnerability affects Flash Player for Windows, Mac OS X, Linux, Solaris, and Android, and also impacts the authplay.dll component included in Adobe Acrobat and Adobe Reader X.
A successful exploit of the Flash vulnerability could crash the system, or allow the attacker to take complete control of the affected system. Adobe reports that the flaw is being actively exploited in the wild in targeted attacks using a malicious Flash file (SWF) embedded in a Microsoft Excel (XLS) e-mail file attachment. There are not yet any reports of attacks targeting Adobe Acrobat or Adobe Reader, and Adobe stresses that the Protected Mode sandbox in Reader X would prevent the malicious exploit from executing.
Adobe is working on a fix for the vulnerability. An update for Flash Player, Acrobat, and some versions of Reader is expected to be available sometime next week. However, because the sandbox protection in the Windows version of Adobe Reader X would protect against this flaw being exploited, Adobe does not plan to update that software until the next regular quarterly update scheduled for June 14.
The Adobe Secure Software Engineering Team (ASSET) Blog post explains, “We considered providing an out-of-cycle update for Adobe Reader X as well, which would have delayed the current patch release schedule by about another week,” adding, “However, given the mitigation provided by the Adobe Reader X sandbox and the absence of attacks via PDF, we determined that an out-of-cycle update would incur unnecessary churn and patch management overhead on our users not justified by the associated risk, in particular for customers with large managed environments.”