Macromedia Flash Bug Could Open Windows PCs To Hackers

June 2001

Users of the Microsoft's Internet Explorer Web browser are being urged to install the latest version of Macromedia's Flash player to protect themselves from a serious security hole in at least one previous release.
Computer security experts say a bug in software for Flash that is launched via ActiveX technology in the Explorer browser could allow evil-doers to gain control of a victim's computer.

While an updated version of the Flash software recently posted by Macromedia plugs the hole, it's not yet known how many PCs are outfitted with software containing the bug first described Wednesday by Eeye Digital Security of Aliso Viejo, Calif.

Complicating the issue further is that many Web users may not be aware that they have Flash installed on their PCs. But Maiffret said any Internet Explorer user with a vulnerable version of the Flash software would be open to attack if they were to visit a Web page specially crafted by hackers or were to receive the malicious exploit via e-mail.

Source...