Adobe Reports Critical Flash Vulnerability

LOS ANGELES — Adobe has issued a warning about a critical vulnerability in the current versions of some of its most popular software products; the latest in a series of similar warnings to affect the software giant.

According to the company, the affected programs are Flash Player (v9.0.159.0 and v10.0.22.87) for Windows, Macintosh and Linux operating systems, and the authplay.dll component that ships with Adobe Reader and Acrobat v9.x for Windows, Macintosh and UNIX operating systems.

"This vulnerability (CVE-2009-1862) could cause a crash and potentially allow an attacker to take control of the affected system," stated a company release. "There are reports that this vulnerability is being actively exploited in the wild via limited, targeted attacks against Adobe Reader v9 on Windows."

Adobe is in the process of developing a fix and expects to provide an update for Flash Player before July 30 and an update for Adobe Reader and Acrobat by July 31.

"Deleting, renaming, or removing access to the authplay.dll file that ships with Adobe Reader and Acrobat v9.x mitigates the threat for those products, but users will experience a non-exploitable crash or error message when opening a PDF that contains SWF content," Adobe advises.

According to the company, the authplay.dll that ships with Adobe Reader and Acrobat 9.x for Windows is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll or C:\Program Files\Adobe\Acrobat 9.0]\Acrobat\authplay.dll.

"Windows Vista users should consider enabling UAC (User Access Control) to mitigate the impact of a potential exploit. Flash Player users should exercise caution in browsing untrusted websites," Adobe further cautioned, adding that "Adobe is in contact with Antivirus and Security vendors regarding the issue and recommend users keep their anti-virus definitions up to date."

John Bambenek of US-CERT's SANS Internet Storm Center says that the vulnerability is currently being exploited by malicious sites as well as via link injection into legitimate websites as part of a drive-by attack.

US-CERT is advising Windows users to disable Flash in Adobe Reader 9 and to disable the Flash Player — a move which would render most tube sites unusable to their visitors and brings with it broader implications for the online adult community and consumer's access to our wares.

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Italian Court in Aylo Case Limits International Reach of AV Rules

An Italian administrative court has ruled that Italy’s recently-enacted age verification rules for adult content may not currently be enforced against sites based in other EU member states, pending further procedural action under the EU’s Directive on Electronic Commerce.

OCC, FDIC Prohibit Use of 'Reputation Risk' by Regulators

The Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC) on Tuesday issued a final rule codifying the elimination of ‘reputation risk’ from their supervision of financial institutions.

Wisconsin Governor Vetoes Age Verification Bill

Gov. Tony Evers on Friday vetoed AB 105, an age verification bill that would have allowed anyone to sue adult content providers for damages over alleged failure to age-verify users in Wisconsin, with penalties of up to $10,000 per violation.

FSC Releases Statement on Wisconsin Governor Vetoing AV Bill

The Free Speech Coalition has released a statement on Wisconsin Governor Tony Evers' veto of the state's age verification legislation.

AV Bulletin: West Virginia Enacts AV Law, Ohio 'Innocence Act' Advances

This roundup provides an update on the latest news and developments on the age verification front as it impacts the adult industry.

Woodhull Survey Reveals Concern Among Sex Educators Over AV Laws' Impact on Access

A national survey of sex educators by the Woodhull Freedom Foundation found that a majority of sex educators and sexual health professionals are concerned that age verification (AV) laws will negatively impact access to information and resources.

Clips4Sale Wins Trademark Infringement Case Against Fraudulent Domain

The World Intellectual Property Organization (WIPO) has ruled in favor of content platform Clips4Sale in a case against a website using a similar domain to impersonate the site.

Pineapple Support, SextPanther to Host Stress Management Support Group

Pineapple Support and SextPanther are hosting a free online support group focused on stress management for performers.

Goddess Tangent Launches New Site Through Grooby's Blue.xxx

Goddess Tangent has launched her new membership site, TangentOD.com, through Grooby's website management company Blue.xxx.

Show More