A researcher has unearthed a bug in software used to install Adobe's ubiquitous Reader and Flash applications that can be exploited to remotely install malicious files on end user PCs.
The Adobe Download Manager is an ActiveX script that is invoked when people install or update
Reader or
Flash using Internet Explorer. Researcher Aviv Raff has figured out how to exploit it to install any file he wishes simply by tricking a user into clicking on a link on the Adobe.com domain.