News

Adobe: Eclipsing Microsoft as Patch Concern?

All eyes tend to focus on Microsoft's monthly patch cycle, but don't forget Adobe.

Microsoft's January security patch contained just one Windows fix, but IT pros likely will have to spend some time plugging holes in Adobe products too this month.

"It was a relatively light month in terms of Microsoft," said Ben Greenbaum, senior research manager at Symantec Security Response. "But because Adobe is addressing a number of security holes, at least one of them critical, IT administrators will still be busy."

On Tuesday, Microsoft released a security advisory about an Adobe vulnerability affecting Windows XP. On that same day, Adobe released patches of its own for several of its applications. The patches address Adobe Reader 9.2, Acrobat 9.2, Adobe Reader 8.1.7 and Acrobat 8.1.7 for Windows and Macintosh. There's also a patch for Adobe Reader 9.2 for Unix-based operating systems.

Last week, Adobe issued security patches for its Illustrator graphics program.

"After a solid year of security issues, Adobe's product security and secure product development practices are being seriously questioned," said Andrew Storms, director of security at nCircle. "It's ironic to consider that we may have reached the point where Microsoft Office documents are now more secure than [Adobe] PDF documents."

Microsoft's latest security advisory refers to a vulnerability in Adobe Flash Player 6 for Windows XP-based systems. The vulnerability, involving ActiveX controls, has been addressed in newer releases of the Adobe's software, according to Microsoft.

Microsoft recommends removing Adobe Flash Player 6 from XP-based systems and installing the newest Flash Player software. To remove the software, Microsoft points to this Adobe instruction page.

About the Author

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.

Featured

  • Exchange Server June Cumulative Updates Arrive, But with Red Tape

    Microsoft released its quarterly cumulative updates (CUs) for Exchange Server 2013, 2016 and 2019 products this week, but added an extra step for IT pros to consider before installing them.

  • Moving an Old VM to a New Hyper-V Host

    So you want to know whether a Hyper-V virtual machine built on a legacy host will be supported by a newer server? There's a PowerShell command for that.

  • AI-Driven Solution Tracks Packets Through the Datacenter

    Datacenter solutions vendor Kaloom this week unveiled a new offering the company says will enable the development of "self-driving" datacenter networks.

  • Microsoft Previews Azure Bastion Service for Private VM Access

    Microsoft on Tuesday announced a preview of the Azure Bastion service, which lets a user connect to an Azure virtual machine (VM) using a private Internet connection.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.