Adobe Warns of Code Injection Hole in Flash Media Server

執筆者
Ryan Naraine
Ryan Naraine
Published: Feb 13, 2008
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Adobe’s security struggles have hit a new gear with three new bulletins warning about “critical” code injection and system takeover vulnerabilities in enterprise-facing products.
On the heels of the recent disclosure hiccup surrounding Adobe Reader, the vendor Feb. 12 released patches for two critical issues affecting the Flash Media Server and the Adobe Connect Enterprise Server.
A third bulletin, rated “important,” provides cover for a cross-site scripting vulnerability affecting RoboHelp 7 and RoboHelp 7 installations.
The most serious of the three issues-in Flash Media Server 2-fixes a total of three flaws that could put business users at risk of remote code injection attacks.
According to iDefense, the company that reported the bugs to Adobe, the Flash Media Server is vulnerable to remote exploitation of multiple integer overflow vulnerabilities.
“[This] could allow an unauthenticated attacker to execute arbitrary code with SYSTEM privileges,” iDefense said. To exploit these vulnerabilities, an attacker only needs the ability to connect to the target server on TCP port 1935 or 19350.
The bugs affect Flash Media Server 2 version 2.0.4 on Windows. Previous versions, as well as the Linux version, may also be affected, iDefense said.
The second critical issue in this Adobe patch batch-three different vulnerabilities in the Adobe Connect Enterprise Server-also puts users at risk of remotely exploitable system takeover attacks.
Attackers would need to be able to connect to TCP port 1935 to exploit this issue, Adobe said.
Earlier this week, Adobe also belatedly shipped a security bulletin to acknowledge several serious issues in the ubiquitous Adobe Reader and Adobe Acrobat products.
Anti-malware vendors have confirmed that the Reader/Acrobat vulnerability is being exploited in the wild with rigged PDF files.

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。