Adobe pushed a critical update to users of their Reader software yesterday, patching a critical vulnerability being exploited to take control of victims’ computers.
The patch is recommended by Adobe for all users of Adobe Reader and Acrobat, XI and earlier. The update impacts Windows, Macintosh, and Linux users for versions 11.0.01, 10.1.5, 9.x, and earlier versions of Adobe’s software. The patch can be downloaded from Adobe’s website, or through the company’s automatic update feature.
Adobe notes that while automatic updates are enabled by default, users can manually check for an update by clicking Help > Check for Updates.
As SecurityWatch reported earlier, the exploit was discovered by the security company FireEye and is reportedly the first to bypass the sandbox technology used by Adobe in their software. In the attacks, victims receive an email with an attached PDF, which in turn contains highly obfuscated JavaScript.
via Adobe Patches Exploit in Acrobat and Reader, Update Now.
