Skip to main content

Adobe patches Flash bug hackers are already exploiting

posted onSeptember 22, 2011
by l33tdawg

Adobe on Wednesday patched six vulnerabilities in Flash Player, including one it admitted is already being exploited by attackers. That vulnerability, identified as CVE-2011-2444, shares some traits with an earlier Flash flaw that was used to target Gmail accounts in June.

Adobe labeled CVE-2011-2444 as a cross-site scripting (XSS) vulnerability, a class of bugs often used by identity thieves to steal usernames and passwords from vulnerable browsers. In this case, browsers were not directly targeted; rather, attackers exploited the ubiquitous Flash Player browser plug-in.

Like the June Flash bug, CVE-2011-2444 was reported to Adobe by Google's security team. Adobe also used almost identical phrasing to describe both CVE-2011-2444 and the June vulnerability in its security advisories.

Source

Tags

Adobe Hackers Software-Programming

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th