Adobe Reports Critical Flash Vulnerability

LOS ANGELES — Adobe has issued a warning about a critical vulnerability in the current versions of some of its most popular software products; the latest in a series of similar warnings to affect the software giant.

According to the company, the affected programs are Flash Player (v9.0.159.0 and v10.0.22.87) for Windows, Macintosh and Linux operating systems, and the authplay.dll component that ships with Adobe Reader and Acrobat v9.x for Windows, Macintosh and UNIX operating systems.

"This vulnerability (CVE-2009-1862) could cause a crash and potentially allow an attacker to take control of the affected system," stated a company release. "There are reports that this vulnerability is being actively exploited in the wild via limited, targeted attacks against Adobe Reader v9 on Windows."

Adobe is in the process of developing a fix and expects to provide an update for Flash Player before July 30 and an update for Adobe Reader and Acrobat by July 31.

"Deleting, renaming, or removing access to the authplay.dll file that ships with Adobe Reader and Acrobat v9.x mitigates the threat for those products, but users will experience a non-exploitable crash or error message when opening a PDF that contains SWF content," Adobe advises.

According to the company, the authplay.dll that ships with Adobe Reader and Acrobat 9.x for Windows is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll or C:\Program Files\Adobe\Acrobat 9.0]\Acrobat\authplay.dll.

"Windows Vista users should consider enabling UAC (User Access Control) to mitigate the impact of a potential exploit. Flash Player users should exercise caution in browsing untrusted websites," Adobe further cautioned, adding that "Adobe is in contact with Antivirus and Security vendors regarding the issue and recommend users keep their anti-virus definitions up to date."

John Bambenek of US-CERT's SANS Internet Storm Center says that the vulnerability is currently being exploited by malicious sites as well as via link injection into legitimate websites as part of a drive-by attack.

US-CERT is advising Windows users to disable Flash in Adobe Reader 9 and to disable the Flash Player — a move which would render most tube sites unusable to their visitors and brings with it broader implications for the online adult community and consumer's access to our wares.

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Luxembourg Media Regulator Fines LiveJasmin for AV Noncompliance

The Luxembourg Independent Audiovisual Authority (ALIA) has levied a fine of 25,000 euros (approximately $28,000) against webcam platform LiveJasmin for failing to comply with provisions of the country’s Electronic Media Law.

AdultHTML Introduces Subscription Option for Website Owners

AdultHTML has added a subscription option for its web development service, allowing site owners to pay a monthly fee for access to developers and tools.

French Parliament Rejects Ban on Purchase of 'Remote' Sexual Services

The French National Assembly has backed off from a proposal to criminalize the purchase, and/or facilitation by online platforms, of sexual services performed remotely by streamers and custom content creators.

2027 XBIZ Exec Awards Pre-Nominations Period Opens

XBIZ is pleased to announce that the pre-nomination period for the 2027 XBIZ Exec Awards, the adult industry’s preeminent career honors, begins Wednesday and runs through Oct. 14.

Takedown Piracy Reports Infiltration, Monitoring of 'Mega.nz' Pirated Content

Takedown Piracy has reported that the organization has successfully infiltrated Mega.nz folders and identified and removed nearly two million instances of stolen content.

Pornhub Unblocks Australia Users on iOS Devices, Citing Apple AV Effectiveness

Pornhub parent company Aylo on Tuesday announced that users in Australia will once again be able to access the popular site if they are using Apple devices and have confirmed their age through Apple’s Australian age-verification process.

California Governor Signs Bill Limiting CIPA Claims

Governor Gavin Newsom has signed into law a bill to narrow the scope of the California Invasion of Privacy Act (CIPA), to prevent abusive lawsuits targeting online businesses, including adult websites.

California Enacts Stricter UGC Rules for Adult Sites

Governor Gavin Newsom has signed into law a bill to impose tighter compliance standards for user-generated content (UGC) on adult websites accessible in California.

Minister: UK Aims to Begin Enforcing 'Choking' Ban Before Year's End

The U.K. will soon begin enforcement of a new law criminalizing depictions of “non-fatal strangulation” in adult content, according to a Ministry of Justice official.

XBIZ LA Conference Website Now Live, Registration Open

The event website for the XBIZ LA conference is now live, offering comprehensive information about the upcoming event, taking place Jan. 7-10 at the JW Marriott L.A. LIVE.

Show More