Thursday July 23, 2009

Zero-Day Bug Found in Adobe Flash

Symantec has posted an advisory warning of attacks using malicious PDF files that exploit a zero-day bug in Adobe’s Flash.

Recently we came into possession of an Adobe Acrobat PDF file that upon opening drops and executes a malicious binary. It was quite clear that this PDF was exploiting some vulnerability in order to drop its payload. And, during the analysis it soon became apparent that this vulnerability was not one we had seen in the wild before. What was even more surprising was that this vulnerability affects Adobe Flash—not Adobe Reader as we initially suspected.

Comments