Should Adobe auto-update Flash and PDF Reader?

This year has seen Adobe plugin exploits hit the headlines. Is it time that the company automatically updates its software?

Adobe Flash symbol

Adobe needs to find a way to make sure that all of the users of its software are updated automatically, according to a leading security researcher.

Mikko Hypponen, chief security researcher for F-Secure, said that users were not typically found vulnerable through their operating systems, but rather through plugins and add-ons found inside internet browsers.

Advertisement - Article continues below

This means software such as Adobe PDF Reader and Flash, Java or Quicktime. While Windows is updated automatically, these are still left unpatched and therefore vulnerable to new exploits.

This is especially dangerous as Adobe Flash has a bigger market share than even Windows, and Mac and Linux users often had it on their systems. Of these users, 80 per cent ran old Flash.

It is also problematic that users aren't required to click on a Flash or PDF file, as you can get infected by simply browsing a website.

"That's the way that attackers gain way, and if you look at the market share of things like Adobe Flash or the PDF reader plugin, they are huge," said Hyponnen.

"Most of them are not up to date. Microsoft can do this, so Adobe should be able to do this as well."

Security exploits against QuickTime plugins were also an issue, which users often didn't install but found in their systems.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

"It's because I have an iPod," Hyponnen said. "And because I have an iPod I have to install iTunes. When I install it will, without asking me, install QuickTime automatically."

QuickTime automatically installs a plugin inside a web browser, which means that if there is a flaw, it could be exploited.

"I'm not concerned with updating QuickTime. I've never even installed it," he added.

Adobe had not responded to request for comment at the time of publication.

Featured Resources

Top 5 challenges of migrating applications to the cloud

Explore how VMware Cloud on AWS helps to address common cloud migration challenges

Download now

3 reasons why now is the time to rethink your network

Changing requirements call for new solutions

Download now

All-flash buyer’s guide

Tips for evaluating Solid-State Arrays

Download now

Enabling enterprise machine and deep learning with intelligent storage

The power of AI can only be realised through efficient and performant delivery of data

Download now
Advertisement

Recommended

Visit/security/355013/10-quick-tips-to-identifying-phishing-emails
Security

10 quick tips to identifying phishing emails

16 Mar 2020
Visit/business-strategy/mergers-and-acquisitions/354941/panda-security-to-be-acquired-by-watchguard
mergers and acquisitions

Panda Security to be acquired by WatchGuard

9 Mar 2020
Visit/pdf-software/29855/why-it-s-time-to-take-your-documents-digital
document management systems (DMS)

Why it’s time to take your documents digital

7 Feb 2020
Visit/infrastructure/server-storage/354508/synology-flashstation-fs3400-same-old-same-old
Server & storage

Synology FlashStation FS3400: Same old, same old

9 Jan 2020

Most Popular

Visit/software/video-conferencing/355138/zoom-beaming-ios-user-data-to-facebook-for-targeted-ads
video conferencing

Zoom beams iOS user data to Facebook for targeted ads

27 Mar 2020
Visit/infrastructure/server-storage/355118/hpe-warns-of-critical-bug-that-destroys-ssds-after-40000-hours
Server & storage

HPE warns of 'critical' bug that destroys SSDs after 40,000 hours

26 Mar 2020
Visit/software/355113/companies-offering-free-software-to-fight-covid-19
Software

These are the companies offering free software during the coronavirus crisis

25 Mar 2020
Visit/mobile/mobile-phones/355088/apple-lifts-iphone-purchase-restrictions
Mobile Phones

Apple lifts iPhone purchase restrictions

23 Mar 2020