Showing posts with label Adobe Flash. Show all posts
Showing posts with label Adobe Flash. Show all posts
Sunday
Disabling Flash in browser may not be enough to secure your machines
Disabling Flash in your PC browser may help stave off online attacks, but it may still not be enough, a security vendor warns.
Fortinet said Flash files can also be embedded in various document formats including Microsoft Office documents and even PDF files.
"Even if you have disabled Flash in your browsers, Flash exploits can still leverage Flash player vulnerabilities through software like Microsoft Office and Adobe Reader," Fortinet's Bing Liu said in a blog post.
As proof of concept, Liu crafted a PowerPoint file that would cause the caculator program to pop up when loaded in apps with a vulnerable Flash plugin.
The Flash exploit "works well inside a PPT and PDF document until I uninstall the Flash player on my computer," Liu said.
Such a situation "is just one simple example of ways in which Flash can be exploited outside of a web browser," Liu added.
"What all this means, unfortunately, is that disabling the Flash plugin in your browsers isn't a complete solution to Flash security. Flash is a technology that can be embedded in many places and requires vigilance on the part of users as well as smart edge and endpoint protection and rigorously patched software to ensure that Flash exploits don't end up on your network," Liu said. — Joel Locsin/LBG, GMA News
source: gmanetwork.com
Friday
Adobe patches flaw in Flash but another one found
Users of some browsers may want to put off visiting sites that use Adobe's Flash software – Adobe has patched a flaw in Flash, but a new one has been discovered.
Adobe this week rolled out a patch to address a vulnerability being exploited by the Angler Exploit Kit, but a security researcher found it was not the only flaw.
"Any version of Internet Explorer or Firefox with any version of Windows will get owned if Flash up to 16.0.0.287 (included) is installed and enabled," researcher "Kafeine" said in a blog post.
"Disabling Flash player for some days might be a good idea," Kafeine added.
On Jan. 22, Adobe issued a security update for a vulnerability affecting Flash Player for Windows, Mac and Linux.
It urged users to update to Flash Player 16.0.0.287.
But Kafeine noted that Angler initially did not infect Firefox, Angler's encoders made the adjustments so it would also affect Mozilla's browser.
So far, Kafeine said tests showed Google's Chrome is relatively safe from the threat. — Joel Locsin/LBG, GMA News
source: gmanetwork.com
Subscribe to:
Posts (Atom)


