News

Adobe: Eclipsing Microsoft as Patch Concern?

All eyes tend to focus on Microsoft's monthly patch cycle, but don't forget Adobe.

Microsoft's January security patch contained just one Windows fix, but IT pros likely will have to spend some time plugging holes in Adobe products too this month.

"It was a relatively light month in terms of Microsoft," said Ben Greenbaum, senior research manager at Symantec Security Response. "But because Adobe is addressing a number of security holes, at least one of them critical, IT administrators will still be busy."

On Tuesday, Microsoft released a security advisory about an Adobe vulnerability affecting Windows XP. On that same day, Adobe released patches of its own for several of its applications. The patches address Adobe Reader 9.2, Acrobat 9.2, Adobe Reader 8.1.7 and Acrobat 8.1.7 for Windows and Macintosh. There's also a patch for Adobe Reader 9.2 for Unix-based operating systems.

Last week, Adobe issued security patches for its Illustrator graphics program.

"After a solid year of security issues, Adobe's product security and secure product development practices are being seriously questioned," said Andrew Storms, director of security at nCircle. "It's ironic to consider that we may have reached the point where Microsoft Office documents are now more secure than [Adobe] PDF documents."

Microsoft's latest security advisory refers to a vulnerability in Adobe Flash Player 6 for Windows XP-based systems. The vulnerability, involving ActiveX controls, has been addressed in newer releases of the Adobe's software, according to Microsoft.

Microsoft recommends removing Adobe Flash Player 6 from XP-based systems and installing the newest Flash Player software. To remove the software, Microsoft points to this Adobe instruction page.

About the Author

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.

Featured

  • Image of a futuristic maze

    The 2024 Microsoft Product Roadmap

    Everything Microsoft partners and IT pros need to know about major Microsoft product milestones this year.

  • Microsoft Sets September Launch for Purview Data Governance

    Microsoft's AI-powered Purview solution to address governance and security challenges is set to become generally available on Sept. 1.

  • An image of planes flying around a globe

    2024 Microsoft Conference Calendar: For Partners, IT Pros and Developers

    Here's your guide to all the IT training sessions, partner meet-ups and annual Microsoft conferences you won't want to miss.

  • End of the Road for Kaspersky in the United States

    Kaspersky on Monday said it is shuttering its U.S. operations, just days before a nationwide ban on sales of its security software was set to take effect.