Serious flaws patched for Adobe Reader and Windows 2000
- 13 January, 2010 12:03
- Comments
Today's post-holiday Patch Tuesday included just one bulletin, which is rated critical only for Windows 2000, but Adobe also released a must-have Reader update.
Microsoft's MS10-001 security bulletin addresses a flaw with Embedded OpenType fonts that can be attacked through any program that can render the fonts, including Internet Explorer, PowerPoint or Word. A successful attack could hand over complete control of a vulnerable system, according to the bulletin, but only Windows 2000 is vulnerable.
Other versions of Windows "contain the vulnerable code but do not use this code in a way that may expose the vulnerability," according to the bulletin. If you have a Windows 2000 system you'll get this fix via Windows Update.
On the other hand, all Windows, Macintosh and Unix systems with Adobe Reader 9.2 or Acrobat 9.2 will need a program update to version 9.3 to close an under-attack security flaw that has been targeted with poisoned .pdf files. Acrobat versions 8.1.7 and earlier will likewise require an upgrade to version 8.2. Heading to Help | Check for Updates will get you the update, or download the full 9.3 version. For more details see Adobe's bulletin.
Nominations for the 2012 ARN IT Industry Awards open on Tuesday, June 12.
- Bookmark this page
- Share this article
- Got more on this story? Email ARN
- Follow ARN on twitter
- Microsoft Security Bulletin MS10-001 - Critical: Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution (972270)
- New Year, New Attacks Against Adobe Zero-Day - PC World
- Adobe - Adobe Reader download - All versions
- Adobe - Security Bulletin APSB10-02 Security Advisory for Adobe Reader and Acrobat
- In Search of the Long-Term Archiving Solution —Tape Delivers Significant TCO Advantage over Disk
- Spectra Logic and Australian National University Success Story - March 2012
- Premier Media Group Fast Study
- Red Light In the Control Centre Saves Hours of Chaos
- Market Potential-Strategy Guide to the Active Archive Market
-
It's not all Doom at new media conference
-
Tech Watch: Who watches the datacentre?
-
Facebook scammers host Trojan horse extensions on the Chrome Web Store
-
Webroot: Growth in security
-
Sice quits Acronis, joins Staples














Comments
Post new comment