WARNING--Adobe Download/Reader Download Manager v2.1 has Security Flaw

According to this Adobe Security Bulletin,

A critical vulnerability has been identified in Adobe Download Manager 2.1 and earlier versions that could allow an attacker who successfully exploits this vulnerability to take control of the affected system. This issue is remotely exploitable. A malicious file must be loaded by the end user, via a web browser or e-mail client for instance, for an attacker to exploit this vulnerability. It is recommended that users uninstall Adobe Download Manager 2.1 and earlier using the instructions provided below.

Adobe Download Manager is a stand-alone application that improves the process of downloading files from Adobe. Customers who have downloaded software from Adobe, including Adobe Reader, may have Adobe Download Manager installed.

As of December 5, 2006, software distributed from www.adobe.com is using Adobe Download Manager 2.2, which is not affected by this issue.

So if you have downloaded any Adobe software, like Adobe Reader 8, before 12/5/06, you probably need to uninstall Adobe Download Manager v2.1 or Adobe Reader Download Manager v2.1 or earlier using an Adobe uninstaller available from this Adobe Web page. But check the version to make sure using Get Info. Most of our Macs had v2.2 but our Intel-based Mac mini had v2.1.

We downloaded and used the uninstaller on our Intel-based Mac mini with no problem. [Bill Fox]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive