Adobe Issues Critical Flash Player Update

Adobe Issues Critical Flash Player Update

Written By
Ryan Naraine
Ryan Naraine
Apr 9, 2008
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Adobe Systems has released a major Flash Player update to fix at least seven cross-platform vulnerabilities that put users at risk of PC takeover attacks.

One of the vulnerabilities covered in the APSB08-11 update was used to hijack a Windows Vista laptop at the CanSecWest “Pwn to own” hacking contest March 26-28.

The update is available for Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier.

“Critical vulnerabilities have been identified in Adobe Flash Player that could allow an attacker who successfully exploits these potential vulnerabilities to take control of the affected system. A malicious SWF must be loaded in Flash Player by the user for an attacker to exploit these potential vulnerabilities,” Adobe said in an advisory.

Because some of these security fixes may cause problems on Web sites that use Flash content, Adobe has released a separate advisory with instructions on “necessary changes” needed to ensure a seamless transition.

To read about Adobe’s warning of a code injection hole in Flash Media Server, click here.

According to Adobe, the most serious of the seven vulnerabilities “could lead to the potential execution of arbitrary code” if users simply surfed to a booby-trapped Web site or opened an e-mail with Flash content.

The update introduces functionality to mitigate two known flaws that could help an attacker to launch a DNS (Domain Name System) rebinding attack; a new method for the Flash Player to interpret cross-domain policy files; a new security feature that performs a cross-domain policy file check before allowing SWFs to send HTTP headers to another domain; and a major change in Flash Player’s “AllowScriptAccess” default.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.