This author has long advised computer users who have Adobe‘s Shockwave Player installed to junk the product, mainly on the basis that few sites actually require the browser plugin, and because it’s yet another plugin that requires constant updating. But I was positively shocked this week to learn that this software introduces a far more pernicious problem: Turns out, it bundles a component of Adobe Flash that is more than 15 months behind on security updates, and which can be used to backdoor virtually any computer running it.
My re-education on this topic comes courtesy of Will Dormann, a computer security expert who writes threat advisories for Carnegie Mellon University’s CERT. In a recent post on the release of the latest bundle of security updates for Adobe’s Flash player, Dormann commented that Shockwave actually provides its own version of the Flash runtime, and that the latest Shockwave version released by Adobe has none of the recent Flash fixes.
Worse yet, Dormann said, the current version of Shockwave for both Windows and Mac systems lacks any of the Flash security fixes released since January 2013. By my count, Adobe has issued nearly 20 separate security updates for Flash since then, including fixes for several dangerous zero-day vulnerabilities.
“Flash updates can come frequently, but Shockwave not so much,” Dormann said. “So architecturally, it’s just flawed to provide its own Flash.”
Shockwave sometimes holds up loading of websites. Just need to know if i need both Adobe and shockwave both or can shockwave be deleted?
Dormann said he initially alerted the public to this gaping security hole in 2012 via this advisory, but that he first told Adobe about this lackluster update process back in 2010.
As if that weren’t bad enough, Dormann said it may actually be easier for attackers to exploit Flash vulnerabilities via Shockwave than it is to exploit them directly against the standalone Flash plugin itself. That’s because Shockwave has several modules that don’t opt in to trivial exploit mitigation techniques built into Microsoft Windows, such as SafeSEH.
“So not only are the vulnerabilities there, but they’re easier to exploit as well,” Dormann said. “One of the things that helps make a vulnerability more difficult [to exploit] is how many of the exploit mitigationsa vendor opts in to. In the case of Shockwave, there are some mitigations missing in a number of modules, such as SafeSEH. Because of this, it may be easier to exploit a vulnerability when Flash is hosted by Shockwave, for example.”
Adobe spokeswoman Heather Edell confirmed that CERT’s information is correct, and that the next release of Shockwave Player will include the updated version of Flash Player.
“We are reviewing our security update process in order to mitigate risks in Shockwave Player,” Edell said.
1,514 ready-to-use business form templates that you can download and print for free. Or download the entire collection for just $47. There's no need to make business forms from scratch — we've done it for you. Choose from letters, reports, log sheets, forms, and more. Simplify your data collection efforts and automate your workflows with these 1900+ web form templates that blend in smoothly on your website. Customize any of the form examples that you find by using the 123FormBuilder platform. JotForm offers the largest selection of free form templates available online. No matter what information you need, whether it’s applications, order details, or feedback, we’ve got online forms of every type, for every industry. Customize any template to suit your specific needs with our drag-and-drop form builder. Choose from hundreds of free Microsoft Word templates online. Distinctive document designs help you create printable calendars, newsletters, flyers, resumes, brochures, and more for any occasion. Forms templates free.
Do I Need Adobe Shockwave Player 11.6
Corrector yui episodes. For those who need Shockwave Player installed for some reason, Microsoft’s Enhanced Mitigation Experience Toolkit (EMET 4.1 or higher)) can help prevent the exploitation of this weakness.
Not sure whether your computer has Shockwave installed? If you visit this link and see a short animation, it should tell you which version of Shockwave you have installed. If it prompts you to download Shockwave (or in the case of Google Chrome for some reason just automatically downloads the installer), then you don’t have Shockwave installed. To remove Shockwave, grab Adobe’s uninstall tool here. Mozilla Firefox users should note that the presence of the “Shockwave Flash” plugin listed in the Firefox Add-ons section denotes an installation of Adobe Flash Player plugin — not Adobe Shockwave Player.
Tags: Adobe Shockwave, CERT, EMET, Enhanced Mitigation Experience Toolkit, Heather Edell, Macromedia Flash, Will Dormann