NY.gov Portal State Agency Listing
The following cyber advisory was issued by the New York State Office of Cyber Security (OCS) and is
intended for State government entities. The information may or may not be applicable to the
general public and accordingly, the State does not warrant its use for any specific purposes.

OCS ADVISORY NUMBER:
2011-017 Updated

DATE(S) ISSUED:
4/12/2011
4/18/2011 - UPDATED
4/22/2011 - UPDATED

SUBJECT:
Vulnerability in Adobe Flash Player Could Allow For Remote Code Execution

ORIGINAL OVERVIEW:

A vulnerability has been discovered in Adobe Flash Player which could allow attackers to take complete control of an affected system. Adobe Flash Player is a widely distributed multimedia and application player used to enhance the user experience when visiting web pages or reading e-mail messages. This vulnerability may be exploited if a user opens a Microsoft Word document containing an embedded specially crafted Adobe Flash file, which may be sent as an e-mail attachment. Successful exploitation will cause the application to crash and could also result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions.

It should be noted that there have been reports of active exploitation of this vulnerability.

Adobe Reader 9.x for UNIX, Adobe Reader for Android, and Adobe Reader and Acrobat 8.x are not affected by this issue.

APRIL 18 - UPDATED OVERVIEW:
Adobe has released updates for Flash Player and Air for Windows, Macintosh, Linux, and Solaris. Please note that Adobe expects updates for Adobe Flash Player 10.2.156.12 and earlier versions for Android to be available the week of April  25, 2011.

APRIL 22 - UPDATED OVERVIEW:
Adobe has released updates for Adobe Reader and Acrobat for Windows, and Macintosh.

SYSTEMS AFFECTED:

  • Adobe Flash Player 10.2.153.1 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems.
  • Adobe Flash Player 10.2.154.25 and earlier for Chrome users.
  • Adobe Flash Player 10.2.156.12 and earlier for Android.
  • The authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.2) and earlier 10.x and 9.x versions for Windows and Macintosh operating systems.

RISK:
Government:

  • Large and medium government entities: High
  • Small government entities: High

Businesses:

  • Large and medium business entities: High
  • Small business entities: High

Home users: High

ORIGINAL DESCRIPTION:
Adobe Flash Player is prone to a vulnerability that allows for remote code execution. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely cause denial-of-service conditions. There have been reports indicating active exploitation of this vulnerability due to opening a Microsoft Word (.doc) file sent as an e-mail attachment and embedded with a specially crafted Flash (.swf) file. Users should assume this vulnerability could be exploited in any rich content capable file format at this time.

Adobe is reporting that this vulnerability may also impact the authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.2) and earlier 10.x and 9.x versions for Windows and Macintosh operating systems. However, Adobe is not currently aware of attacks targeting Adobe Reader and Acrobat when opening PDF files. Adobe Reader X with Protected Mode enabled would prevent an exploit of this kind from executing.

It should be noted that there have been reports of active exploitation of this vulnerability.

Adobe Reader 9.x for UNIX, Adobe Reader for Android, and Adobe Reader and Acrobat 8.x are not affected by this issue.

APRIL 18 - UPDATED DESCRIPTION:
Adobe has released updates for Flash Player and Air for Windows, Macintosh, Linux, and Solaris. Please note that Adobe expects updates for Adobe Flash Player 10.2.156.12 and earlier versions for Android to be available the week of April  25, 2011.

APRIL 22 - UPDATED DESCRIPTION:
Adobe has released updates for Adobe Reader and Acrobat for Windows, and Macintosh.

ORIGINAL RECOMMENDATIONS:
We recommend the following actions be taken:

  • Install the patch/update from Adobe as soon as it becomes available after appropriate testing.
  • Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack.
  • Consider installing and running Adobe Reader X in Protected Mode.
  • Do not open e-mail attachments from unknown or un-trusted sources.
  • Consider implementing file extension whitelists for allowed e-mail attachments.

APRIL 18 - UPDATED RECOMMENDATIONS:
We recommend the following actions be taken:

  • Install the patch/update from Adobe immediately after appropriate testing.

APRIL 22 - UPDATED RECOMMENDATIONS:
We recommend the following actions be taken:

  • Install the patch/update from Adobe immediately after appropriate testing.

ORIGINAL REFERENCES:

Adobe:
http://www.adobe.com/support/security/advisories/apsa11-02.html

SecurityFocus:
http://www.securityfocus.com/bid/47314

CVE:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0611

APRIL 18 - UPDATED  REFERENCES:
Adobe:
http://www.adobe.com/support/security/bulletins/apsb11-07.html

APRIL 22 - UPDATED  REFERENCES:
Adobe:
http://www.adobe.com/support/security/bulletins/apsb11-08.html

Security Focus:
http://www.securityfocus.com/bid/47531

CVE:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0610