Adobe finds exploited flaw in Flash Player
The company fixes one flaw and just as another appears.

Adobe has reported a serious flaw in its Flash Player and in a component of Reader and Acrobat that, when exploited, could allow an attacker to take control.
The company's developers are having a busy time. This flaw was reported just as Adobe released a large 10-vulnerability patch that included a fix for a previous flaw found in the Shockwave player.
The new vulnerability spreads across many versions of Flash, Reader and Acrobat and the company said that the fix it has started working on will take over a week to be finalised. The latest release, version 10, will be patched after 9 November, the company has promised, and earlier versions will be covered after
15 November.
Until these fixes are released, Adobe advises users to delete or rename the "authplay.dll" file that ships with version 9 of Reader and Acrobat. The applications will still work unless the PDF file contains Flash content. If a Flash component is accessed the application will crash. Instructions for disabling the dll can be found in advisory CVE-2010-3654 on the Adobe site.
Flash Player version 10.1.85.3 and earlier versions are affected on Windows, Macintosh, Linux and Solaris operating systems, as well as 10.1.95.2 and earlier versions for Android.
The flaw also impacts the authplay.dll component in Adobe Reader 9.4 and earlier 9.x versions for Windows, Macintosh and Unix systems, as well as Acrobat 9.4 and earlier 9.x versions for Windows and Macintosh.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
-
Michael Dell talks up the power of human and AI collaboration – but not everyone’s singing the same tune
JPMorgan Chase head of technologies outlines plans for greater generative AI use at Dell Technologies World 2025
-
Dell Technologies Global Partner Summit 2025 – all the news and updates live from Las Vegas
Keep up to date with all the news and announcements from the annual Dell Technologies Global Partner Summit in Las Vegas
-
Vulnerability management complexity is leaving enterprises at serious risk
News Fragmented data and siloed processes mean remediation is taking too long
-
Beat cyber criminals at their own game
Whitepaper A guide to winning the vulnerability race and protection your organization
-
Same cyberthreat, different story
Whitepaper How security, risk, and technology asset management teams collaborate to easily manage vulnerabilities
-
Warning issued over “incomplete” fix for Adobe ColdFusion vulnerability
News An incomplete fix for a vulnerability disclosure could be placing users at risk, researchers warned
-
Three steps to transforming security operations
Whitepaper How to be more agile, effective, collaborative, and scalable
-
Should your business start a bug bounty program?
In-depth Big tech firms including Google, Apple and Microsoft offer bug bounty programs, but can they benefit smaller businesses too?
-
Accessing the XDR realm
Whitepaper A guide for MSPs to unleash modern security
-
Why zero trust strategies fail
In-depth Zero Trust is the gold standard for organizations in protecting systems from cyber attacks, but there are many common implementation pitfalls businesses must avoid