Skip to main content
  1. Home
  2. Computing
  3. Mobile
  4. Web
  5. Legacy Archives

Adobe Flash under fire with another zero-day exploit

Add as a preferred source on Google

Less than a week after warning users about a zero-day exploit in its PDF software, Adobe found another zero-day exploit in Flash. Adobe said hackers are already taking advantage of a critical flow in the current version of Flash to attack Windows PCs to “cause a crash and potentially allow an attacker to take control.”

Despite Adobe’s claims that the attacks are “limited” and “targeted” only at Windows users, the flaw is pretty far-reaching. All editions of Flash 9 and 10, including those for Windows, Mac, Linux, Solaris, and Google’s Android mobile operating system, and earlier versions, are affected. It’s also present in Adobe Reader and Acrobat, as well, since both programs include code to run Flash embedded in PDF documents. There are no reports of hackers exploiting the bug in PDF applications at this time, according to the company.

Recommended Videos

Technical details of the exploit were not disclosed, but a fix is already in the works. The company will release a patch for Flash in two weeks, or the week of Sept. 27; Acrobat and Reader will have to wait an extra week longer, or the week of Oct. 4, for a patch. Instead of waiting for the normal update on Oct. 12, these patches will be pushed out as an “out of band” security update.

Flash and Reader are Adobe’s two most prominent applications and frequently under attack by hackers. There have been three emergency patches for Reader over the past three months. The latest zero-day exploit reported earlier this month involved JavaScript. For users waiting for the patch, Microsoft announced Sept. 10 that Microsoft’s Enhanced Mitigation Experience Toolkit 2.0 offers some protection against ongoing attacks.

Flash was updated via another emergency patch in June to close a zero-day hole.

All this is just enough to make us wonder again if Steve Jobs is onto something with his adamant refusal to allow Flash on the iPhone and iPad.

Fahmida Y. Rashid
Former Digital Trends Contributor
Asus puts the outrageous dual-screen ROG Zephyrus Duo on the shelf at an eye-watering price
The ROG Zephyrus Duo isn't just a gaming laptop with two screens, it's the company’s most serious attempt yet to add more ambition to a "portable workstation" that’s capable of gaming.
Asus dual-screen laptop America.

Asus has decided that one screen isn’t simply enough on a laptop. The ROG Zephyrus Duo has returned to the market with two screens, with pre-orders now live for what the company is calling the world’s first 16-inch dual-screen gaming laptop.

Starting at $4,499.99 and going up to $5,499.99 for the top configuration, this is undoubtedly a machine that is built for people measuring their laptops with ambition, either for innovation or the desire to game on a dual-screen laptop. 

Read more
Nvidia quietly released a new version of GeForce RTX 5070 GPU inside a driver blog post
And more VRAM doesn't always mean more performance, and the pricing could make the RTX 5070 Ti a better value depending on final configurations.
The RTX 5070 in a graphic.

Nvidia just announced a new GPU variant in the weirdest way possible: buried it in a game driver update blog post. 

Alongside the release of its Game Ready 596.36 WHQL driver, the company also confirmed the launch of a 12GB GDDR7 configuration of the GeForce RTX 5070 laptop GPU. 

Read more
Dell 34 Plus USB-C monitor review: An ultrawide beauty with surprises you’ll love
Dell's curved monitor blends practical minimalism with a few neat perks of its own.
Dell 34 Plus USB-C Monitor - S3425DW

Quick Take

I’ve grown deeply suspicious of any monitor that calls itself a “productivity display.” They're not bad, per se. The real reason is that most of them are boring, and sluggish at adopting modern standards. Chunky black bezels, boring grey-on-grey corporate look that screams “I belong in a 2014 cubicle,” and a dull desk presence. I’ve never wanted any of them sitting on my workstation. So when I unboxed the Dell 34 Plus USB-C monitor (SKU is S3425DW), I was bracing for the usual disappointment. It was in for a surprise.

Read more