Adobe patches Flash again
Posted by: Timothy Weaver on 11/26/2014 11:30 AM
[
Comments
]
Adobe has posted an update to address a critical remote-code-execution vulnerability.
This is the Photoshop giants second attempt to fix this flaw. The vulnerability was first exploited by the Angler malware kit to infect computers and inject malicious code into running processes.
The first fix seemed to shut the door to the virus, but it only took two days for the hackers to tweak their malware code to continue with the attacks.
F-Secure said.: "We considered the possibility that maybe the latest patch [from October] prevented the exploit from working and the root cause of the vulnerability was still unfixed, so we contacted the Adobe Product Security Incident Response Team. They confirmed our theory and released an out-of-band update to provide additional hardening against a vulnerability in the handling of a dereferenced memory pointer that could lead to code execution."
The first fix seemed to shut the door to the virus, but it only took two days for the hackers to tweak their malware code to continue with the attacks.
F-Secure said.: "We considered the possibility that maybe the latest patch [from October] prevented the exploit from working and the root cause of the vulnerability was still unfixed, so we contacted the Adobe Product Security Incident Response Team. They confirmed our theory and released an out-of-band update to provide additional hardening against a vulnerability in the handling of a dereferenced memory pointer that could lead to code execution."
Comments