Follow Us

Adobe Download Manager security bug could give hackers access

Flaw could give an attacker a way to install an unwanted program

Adobe Systems is working to fix a glitch in software it uses to speed up downloads of its products that could give hackers a way to push malicious programs onto a victim's PC.

According to security researcher Aviv Raff, Download Manager - a small program Adobe users to speed up the initial installation of its products - can be misused to force victims to install unwanted software on their computers.

Because of an undisclosed flaw in the way Download Manager works, the "attacker can force an automatic download and installation of any executable he desires," Raff wrote in a blog post. "So, if you go to Adobe's website to install a security update for Flash, you really expose yourself to a zero-day attack."

Related Articles on Techworld

Adobe said Thursday that it was working with Raff and the third-party developer of the Download Manager product to fix the issue. Download Manager includes an executable program and an ActiveX control or Firefox extension file, depending on which browser is used.

However, it would be hard for a user to install unwanted software without realizing it, because "the user has to accept a number of prompts before being taken through the installation process," said Wiebke Lips, an Adobe spokeswoman, in an e-mailed statement.

The Download Manager is different from Adobe's Update Manger, which is used to patch Adobe software. Download Manager only runs on the computer when software is downloaded, and it removes itself on the next restart. So Raff's attack would only work before that restart removed the Download Manager software.

Still, he believes it is a serious security risk. "This is the kind of scenario that's common when skilled, motivated attackers are going after select targets," Raff wrote on his blog.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Desktop modernisation

On the one hand, there is the need to keep the existing desktop environment efficient, secure...

Download Whitepaper

Top 10 myths about virtualising business-critical applications

Even though virtualization has brought positive change to enterprise IT over the last decade,...

Download Whitepaper

Aligning CFO and CIO priorities

Forward-thinking organisations are viewing cloud computing as an investment in business...

Download Whitepaper

The new corporate network

Businesses can’t afford to have employee productivity suffer because they cannot use their...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...
LogMeIn Rescue

Accelerate Your IT Efficiency

View the latest capacity management resources including whitepapers, videos and news.

Find out more...

Site Map

* *