Symantec backtracks on Adobe Flash warning

A bug originally reported by Symantec to be a new, unpatched vulnerability in Adobe Flash Player was actually patched last month.

After warning on Tuesday that hackers were exploiting an unpatched bug in Adobe Systems' Flash Player software, Symantec has backtracked from this claim, saying the flaw is "very similar" to another vulnerability that was patched last month.

Symantec's initial warning described a disturbing threat -- a previously unknown and unpatched flaw that was being exploited on tens of thousands of Web pages. The flaw allowed attackers to install unauthorized software on a victim's machine and was being used to install botnet programs and password-logging software, Symantec said.

Now Symantec believes that the bug was previously known and patched by Adobe on April 8, said Ben Greenbaum, a senior research manager with Symantec Security Response. However, the Linux version of Adobe's stand-alone Flash Player, version 9.0.124, is vulnerable to the attack.

On Tuesday Symantec researchers saw that the attack worked on Linux and that it caused Flash Player to crash on Windows XP, so they reasoned that they had a new bug that was just not working properly on the Windows platform, possibly due to a programming error by the hackers. "We thought it was a problem with the exploit," he said.

Now Symantec believes that the vulnerability was simply not properly patched in this one version of Adobe's software, Greenbaum said.

That means that Windows and Mac OS X users with the latest updates are not vulnerable, and even Linux users who are running the latest Flash Player plugin inside their browser, rather than as stand-alone software, are safe. However, Windows XP users running the older Flash Player, version 9.0.115, are vulnerable to the attack, Greenbaum said.

This kind of missed security assessment is rare, but it does happen from time to time, said Matt Richard, director of VeriSign's iDefense Rapid Response Team.

"It looks like they just jumped the gun and put it out a little bit too early without doing all the homework," he said of Symantec. "When we did our testing in the lab, the latest version completely fixes the issue: No crashes, no exploits, no nothing."

IBM's Internet Security Systems (ISS), which is credited with discovering the Flash Player bug, echoed Richard's analysis. "Several reports have stated that a zero-day Flash vulnerability is being exploited through several Chinese hacker websites," ISS wrote in its advisory on the flaw. "All of the samples X-Force has seen target the vulnerability disclosed in this Advisory."

In a note on its Web site, Symantec said that it was working with Adobe to figure things out.

An Adobe spokesman said Wednesday that his company was "still trying to get to the bottom of this," but expected to have an update by around noon Pacific time on Wednesday.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Robert McMillan

IDG News Service
Show Comments

Father’s Day Gift Guide

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?