Adobe zero-day flaw code published

A critical vulnerability for Adobe Shockwave Player has been discovered but no patch date has been confirmed.

Adobe Shockwave

The code for a zero-day vulnerability affecting Adobe Shockwave Player has been published and the software maker has not yet promised a patch date.

Adobe acknowledged the hole affecting Shockwave Player 11.5.8.612 and earlier versions on the Windows and Mac operating systems, after a researcher made the exploit code public.

If exploited, the flaw "could cause a crash and potentially allow an attacker to take control of the affected system," Adobe said.

"While details about the vulnerability have been disclosed publicly, Adobe is not aware of any attacks exploiting this vulnerability against Adobe Shockwave Player to date," the firm noted in a security advisory.

Adobe said it is currently working on getting a schedule together for an update to address the vulnerability in Shockwave Player.

The company shares information about this and other vulnerabilities through the Microsoft Active Protections Program, which it joined in July.

Sharing this information with partners in the security community enables them to "quickly develop detection and quarantine methods to protect users until a patch is available," Adobe assured.

"As always, Adobe recommends that users follow security best practices by keeping their anti-malware software and definitions up to date," the firm added.

IT PRO recently caught up with Brad Arkin, Adobe's director for product security and privacy, to talk about how the company tackles serious vulnerabilities such as the above.

Featured Resources

How to scale your organisation in the cloud

How to overcome common scaling challenges and choose the right scalable cloud service

Download now

The people factor: A critical ingredient for intelligent communications

How to improve communication within your business

Download now

Future of video conferencing

Optimising video conferencing features to achieve business goals

Download now

Improving cyber security for remote working

13 recommendations for security from any location

Download now

Recommended

IT security awareness and training firm KnowBe4 acquires MediaPRO
Acquisition

IT security awareness and training firm KnowBe4 acquires MediaPRO

3 Mar 2021
High-risk email security threats increased by 32% last year
phishing

High-risk email security threats increased by 32% last year

3 Mar 2021
The top 12 password-cracking techniques used by hackers
Security

The top 12 password-cracking techniques used by hackers

3 Mar 2021
Microsoft Exchange targeted by China-linked hackers
zero-day exploit

Microsoft Exchange targeted by China-linked hackers

3 Mar 2021

Most Popular

How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

26 Feb 2021
How to connect one, two or more monitors to your laptop
Laptops

How to connect one, two or more monitors to your laptop

25 Feb 2021
How to build a CMS with React and Google Sheets
content management system (CMS)

How to build a CMS with React and Google Sheets

24 Feb 2021