« Spybot Search and Destroy Definitions Updated on 2/25/2009 | Blog Home | My Spam analysis for Feb 23 - Mar 1, 2009 »

Adobe patches critical vulnerabilities in Flash Player

Adobe Flash Player (formerly Macromedia Flash) is a browser plug-in/add-on module that displays active "Flash" multimedia content in web pages. This active content can include audio, video, hyperlinks, and JavaScript. It is thought that Flash Player is installed in over 90% of the personal computers that connect to the Internet. For instance, if you watch YouTube videos on your PC you are doing so via a Flash Player plug-in. Got the picture? So do the bad guys, who are always looking for ways to hijack your PC through Flash vulnerabilities! Some of these vulnerabilities include the ability to forcefully redirect a browser to a hostile file location and download it without the user's knowledge, then execute it. This is currently being exploited by means of specially crafted Flash advertisements made by cyber criminals.

On February 24, 2009, Adobe Flash Player was patched to fix 5 critical vulnerabilities that could allow complete system takeover, without user interaction. This time it not only affects Windows computers, but also Mac OS X and Linux PCs. The new, patched version of Adobe Flash Player is 10.0.22.87. This patch must also be installed into the Adobe CS 4 Flash creation program, if you are a Flash content developer.

Here is a summary of the security advisory published on February 24, 2009...

Adobe Security Advisory APSB09-01

"A potential vulnerability has been identified in Adobe Flash Player 10.0.12.36 and earlier that could allow an attacker who successfully exploits this potential vulnerability to take control of the affected system. A malicious SWF must be loaded in Flash Player by the user for an attacker to exploit this potential vulnerability. Additional vulnerabilities have been addressed in this update. Adobe recommends users update to the most current version of Flash Player available for their platform."

Affected software versions:
Adobe Flash Player 10.0.12.36 and earlier (Adobe Flash Player 10.0.15.3 and earlier for Linux).

Adobe recommends all users of Adobe Flash Player 10.0.12.36 and earlier versions upgrade to the newest version 10.0.22.87 by downloading it from the Player Download Center, or by using the auto-update mechanism within the product when prompted. Only download the Flash Player and its updates from adobe.com! Cyber criminals try to fool people into installing fake Flash players as a means of distributing Botnet Trojans and fake anti virus products.

For users who cannot update to Flash Player 10, Adobe has developed a patched version of Flash Player 9, Flash Player 9.0.159.0, which you can download from this link.

If you use more than one browser you must install the update in each browser separately, by visiting the above-listed download page, as different browsers need different types of Flash. For instance, Interenet Explorer uses an ActiveX version of Flash Player, while Firefox, Opera and others use a browser plug-in version. After you install the update you must restart your browser for the update to "take." This flushes out the [previous version and registers the new one.

After restarting your browser you should go to the About Flash Player page to ensure that you now have the current version installed. I also recommend that you use the Secunia Online Software Inspector scanner to make sure all of your browser's add-ons are up to date, as well as your operating system patches.

I would like to close by stating that users who operate their computers with less than administrator privileges are less at risk from these browser plug-in exploits. Read my recent article about how running your PC with reduced user privileges stops up to 92% of malware infections and its related, linked-to articles.

Get Norton 360

Get Norton 360 Version 4.0 - All-In-One Security. If you have a non-current version of a Symantec security program and wish to renew your definition updates subscription, or upgrade to a new version at a discount, go to the Norton Product Upgrades & Renewals page.

About the author
Wiz FeinbergWiz's Blog is written by Bob "Wiz" Feinberg, an experienced freelance computer consultant, troubleshooter and webmaster. Wiz's specialty is in computer and website security. Wizcrafts Computer Services was established in 1996.

I produce this blog and website at my own expense. If you find this information valuable please consider making a donation via PayPal.


Malwarebytes' Anti-Malware is the most frequently recommended malware removal tool in malware removal forums, like Bleeping Computers. It is extremely effective for removing fake/rogue security alerts, Bots, Spyware and the most prevalent and current malware threats in the wild. Learn about Malwarebytes Anti-Malware.


MailWasher Pro is an effective spam filter that protects your desktop email client. Using a combination of blacklists and built-in and user configurable filters, MailWasher Pro recognizes and deletes spam before you download it. MailWasher Pro reveals the actual URL of any links in a message, which protects you from most Phishing scams. Try it free for 30 days. Pay $39.95 US once, for a lifetime license, with free upgrades.


Get Reliable Web Hosting

BlueHost Web Hosting $6.95

Do you want reliable, yet affordable shared website hosting, with US based phone, email and live chat tech support? If so, you should consider signing up with BlueHost. You can host Unlimited Domains and sub-domains on one account, each complete with their own FTP and Email Accounts. You get unlimited disk space, data transfer & databases, plus dozens of free secured scripts that are easy to install with a few clicks. cPanel Pro control panels support all current web technologies, logs and scripts. All new and transfer accounts are entitled to 1 free domain name and a $50 Google AdWords credit. Pay just $6.95/month, for 2 or 3 years, prepaid. No setup fee and a 30-day money back guarantee. Sign-up with BlueHost Here

Creative Commons License This weblog is licensed under a Creative Commons License.
The content on this blog may be reprinted provided you do not modify the content and that you give credit to Wizcrafts and provide a link back to the blog home page, or individual blog articles you wish to reprint. Commercial use, or derivative work requires written permission from the author.

Start your blog today