Adobe patches under-attack Reader bug
Adobe today issued an emergency update for its popular Reader PDF software that patched two critical vulnerabilities, including one attackers have exploited for weeks.
The more notable flaw fixed in Reader 9.4.1 for Windows and Mac OS X was a bug that hackers have been leveraging since late October using malicious PDF documents. Those attacks have taken advantage of a flaw in Reader's "authplay" component. Authplay is the interpreter that renders Flash content embedded within PDF files.
Successful attacks have dropped a Trojan horse and other malware on victimized Windows PCs. Authplay has been targeted by malware makers several times this year, most recently in June. Then, Adobe shipped an emergency patch for Flash Player within a week, and followed with a fix for Reader and Acrobat two weeks later.