The flaw affects both Adobe's Acrobat and Adobe Reader applications on MacOS and Windows. The company recommends that users of both platforms install the security update.
Such remote code execution flaws are a favorite method for covertly installing malware and are often regarded as the highest risks amongst software vulnerabilities.
Adobe has classified the flaw as 'critical,' the highest of its four security alert levels. The company noted that there is a heightened risk, as the flaw is currently being leveraged by attackers to spread malware in the wild.
Sans security researcher Jason Lam echoed Adobe's sense of urgency, recommending that users install the update as soon as possible.
"This is likely to appear in a malware spreading website near you soon given the track record of the botnet operators," he wrote.
Adobe issues critical fix
By Shaun Nichols on Jun 25, 2008 7:28AM