Adobe Product Fixes Available Now
Some positive news from Adobe last night. Fixes for those nasty vulnerabilities are finally available.
Quick refresher the programs affected are:
- Adobe Flash Player 9.0.159.0 and 10.0.22.87 and earlier 9.x and 10.x versions
- Adobe AIR 1.5.1 and earlier versions
- Adobe Reader and Acrobat 9.1.2 and earlier 9.x versions
The recommendations provided by adobe is that any users of prior versions upgrade them asap.
Linkies to the updates are as follows:
Update for AIR: http://get.adobe.com/air
Update for Reader: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows
Reader will also allow you to update through its own updater
Update for Acrobat: http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows
Just keep in mind that its always a good idea to install updates – reason we’re paying special attention to this one is because it is a critical update which is receiving a lot of publicity. Popular vulnerabilities are more likely to be exploited.
Feel free to shoot us an email or comment with any issues/questions.
Critical Exploit Found in Adobe Products
The US-CERT has published a very serious Adobe flash vulnerability that has been uncovered. The vulnerability affects Adobe Flash versions 9.0.159.0 and 10.0.22.87 and earlier 9.x and 10.x versions. Adobe Reader 9, Acrobat 9, and other Adobe products (including Photoshop CS3, PhotoShop Lightroom, Freehand MX, Fireworks) provide Flash support independent of Flash Player. As of 2009-07-22, Adobe Reader 9.1.2 includes Flash 9.0.155.0, which is likely vulnerable to issues addressed by Flash 9.0.159.0.
This is a very serious vulnerability for which there is currently no patch. It allows an attacker to run malicious code on an affected system. We are systematically disabling the flash component as the temporary fix as we don’t like the provided workaround of deleting, renaming, or removing access to the authplay.dll component which will crash the component.
Adobe is expected to publish a fix on July 30th, which we’ll post here.
Aside from applying patches yourself, we are able to protect you and your organization from 0-day exploits such as this one with our Managed Host Intrusion Prevention system. We’ve been monitoring the exploit for about 2 weeks as it was being stopped cold by the system. With the help of the system we are able to pick up malicious behavior and lock the exploits down before any patches or mentions show up. Shoot us an email for more info.
Stay tuned
Useful links:
http://www.kb.cert.org/vuls/id/259425
http://www.adobe.com/support/security/advisories/apsa09-03.html
Apr, 02 2012
How to Select an Appropriate IT Provider
Mar, 27 2012
Mar, 19 2012
Accidental IT Worker - Does Your Office Have One?
Mar, 15 2012
Oct, 31 2011
Benefits of Using IT Support Company on a Flat Rate
Sep, 09 2011
Finding Computer Support Company for Nursing Facility
Sep, 07 2011
vSphere 5 Is VMware's Jump into Data Storage Virtualization
Aug, 17 2011
Bomgar Analysis and Review at TTIG
Jul, 22 2011
What Do You Know About Your Backup?
Jul, 22 2011
Geopolitical Inputs Into Cloud Computing Decision
Mar, 08 2011
A Popular Hosting Company, Codero, is Attacked With a DDoS From China
Feb, 13 2011
Stuxnet. A War Among Nations – Why Should IT Managers Care?
Aug, 11 2010
AT&T and Verizon Design New Payment System to Compete with Credit Cards
Jul, 11 2010
Will The Perfect Citizen Protect?
Jul, 04 2010
Copper T1 Is One Way To Go, Microwave Wireless Is Another!
Jun, 24 2010
Don't Jump for the iPhone 4 Until You Look At Droid X
Jun, 20 2010
Jun, 09 2010
Microsoft and Adobe Release Critical Security Patches
Feb, 08 2010
Annoying explorer.exe taking up CPU fix
Feb, 07 2010
Biggest Mistakes Companies Make in Selecting an IT Provider or IT Company
Jan, 26 2010
Google Chrome Is Fast and Now Has Bookmark Sync and Extensions
Jan, 26 2010
Cyber Warfare Is Here - What Does That Mean For You?
Jan, 25 2010
Web Remote Workplace Doesn't Work with Internet Explorer - IE 8
Dec, 09 2009
Funny Windows 7 and Chrome Interaction
Nov, 24 2009
IE6 and IE7 vulnerable to latest flaw; IE8 immune
Jul, 23 2009
Oct, 23 2009
New Microsoft Vulnerability Blacklisted by Firefox
Oct, 19 2009
New Vulnerabilities That Concern YOU!
Aug, 01 2009
Adobe Product Fixes Available Now
Jul, 27 2009
Critical Exploit Found in Adobe Products
Jul, 08 2009
Cyber Security And Your Family
Backup Solutions
The TTIG managed backup solution is a safety net on steroids, providing daily motoring and confirmation of the integrity and safety of all data under management. Step into controlled environment of TTIG Disaster Recovery and Data Redundancy Planning.
+ Learn MoreSecurity Solutions
In today's world of data vulnerability, we provide your organization with the best security practices, continuous risk assessments and even managed security monitoring when necessary. Our approach is comprehensive, our solutions increase security. Control Your Data!
+ Read MoreWe centralize our IT Management Process to ensure complete situational awareness through continuous client communication, network monitoring, alerting, and preventative network maintenance. Managed services allow for reduction of downtime through a highly proactive
+ Read More