Adobe patches a critical vulnerability in Shockwave Player

The flaw could enable remote code execution attacks

Adobe Systems released a new security update for Shockwave Player in order to fix a critical vulnerability that could allow attackers to remotely take control of affected systems.

The vulnerability, identified as CVE-2014-0505, is the result of a memory corruption issue and can lead to arbitrary code execution. According to Adobe, the flaw was privately reported to the company and there are no reports of active exploits targeting it in the wild.

Adobe recommends users of Adobe Shockwave Player 12.0.9.149 and earlier versions to update to the newly released version 12.1.0.150, which is available for Windows and Mac, the company said Thursday in a security advisory.

The Shockwave Player update comes two days after Adobe released security patches for vulnerabilities in its more popular Flash Player product.

Shockwave Player installs a browser plug-in that's needed to display interactive online content created with Adobe's Director software. While it's not as widespread as Flash Player, Shockwave Player is deployed on over 450 million desktop computers according to Adobe, which makes it a potential target for hackers.

Join the Computerworld newsletter!

Error: Please check your email address.

Tags patchesonline safetyAdobe Systemssecuritypatch managementExploits / vulnerabilities

More about Adobe SystemsAdobe Systems

CIO
ARN
Techworld
CMO