Alert Number: 062409-02
Alert Date: 06/24/09
Alert Title: Critical vulnerability in Adobe Shockwave player
Update-to: None
OS/Platform/Application:
Adobe Shockwave player
Category: ALERT
Severity: HIGH
Attention: Shockwave users, System Administrators, Desktop Support Personnel
Summary: A critical vulnerability has been discovered in Adobe Shockwave. Shockwave is a popular application for viewing web-based animations and movie files. The most likely mechanism of exploit for this vulnerability is the visitation of a maliciously-crafted website. Successful exploitation of this vulnerability could result in complete takeover of a vulnerable computer.
Recommended Actions: Adobe Systems has released a security advisory detailing the issue and also an update to Shockwave player which fixes the vulnerability. Shockwave users and system administrators are encouraged to read the advisory and install the updated version as soon as possible.
NOTE: Adobe systems recommends removing the current version of Shockwave and restarting your computer prior to installing the new version of Shockwave.
Readers are encouraged to share this alert with family, friends, and associates.
ITS Actions: N/A
Resources:
Adobe security advisory:
http://www.adobe.com/support/security/bulletins/apsb09-08.html