Department of Homeland Security Warns Users to Disable Flash
Adobe has vowed to fix a critical security hole in its Flash software within a week. But the Department of Homeland Security (DoHS) has taken the extremely unusual step of advising users to switch off the feature until the patch is available.
The hole can be used for so-called 'drive by' attacks occurring when a user simply visits an infected website. However, the relevant code is also shared with Adobe's Acrobat software, meaning it can cause security problems through PDF documents which have Flash embedded in them for greater interactivity. That technique had already been criticized as a security risk.
The problem can theoretically affect Windows, Linux and Mac computers. To date, it's only confirmed that hackers have exploited it on Windows machines running Adobe Reader 9.
Critical Fix Due July 30th
Adobe says it expects to have a fix for Flash Player 9 by next Thursday (July 30th) and for Adobe Reader and Acrobat the following day. In the meantime, Adobe advises users to exercise caution visiting websites they may not be able to trust, to make sure antivirus software is up to date, and to consider using User Account Control mode if running Windows Vista.
The firm also suggests users block access to the file named authplay.dll that ships with either Adobe Reader or Acrobat. The easiest way to find this file is to use Windows Search (Start -> Search), type in the filename and search for it.
Once the file is found, rename it to authplay-old.dll (for example), then rename it back to the original filename once the fix has been released. While the file is renamed, users will get an error message and possibly a crash when opening a PDF document with Flash embedded, but the risk of infection will be negated. (Source: adobe.com)
Government Calls For Stronger Action
That advice doesn't go far enough for the Department of Homeland Security. Its Computer Emergency Readiness Team (CERT) advises users to "Disable Flash Player or selectively enable Flash content" until the patch is released. (Source: us-cert.gov)
That would certainly do the trick, though it would mean many web features, including videos on YouTube, would become inaccessible. Depending on the browser/operating combination, users may be able to stop their computers running Flash content by default, while simply clicking to access any content they trust.
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.