3 ms·
Without wanting to go into more details, I work a job that makes me see and analyze more Adobe vulnerabilities than anybody else outside of Adobe. Having said
by sp_ 16y ago
Without wanting to go into more details, I work a job that makes me see and analyze more Adobe vulnerabilities than anybody else outside of Adobe.
Having said that, I run both Flash and Adobe Reader (and Foxit for dubious stuff) on my normal machine. The number of 0-days exploited in the wild is not actually that big (I'd like to see stats here but I am not aware of any) and the odds of being hit by an 0-day exploit is really low. When people get owned through Adobe exploits, it is because they are not updating regularly.
- trotsky 16y agoI definitely agree with you that when (most) people get owned it's because they're not updating regularly - and I don't want to discount your opinion at all as clearly you're in a position to know the risks. But (as I'm sure you know) Adobe does have 0-days quite often and can take weeks to distribute a patch. The sep 14 cve-2010-2883 drop for example was being exploited seemingly quite widely by ~sep 20, and Adobe didn't push a patch until Oct 4. That's a pretty big window to be open to a drive by iframe vuln. Also, doesn't adobe updater take 7 or 14 days between update checks? It used to, at least. The thing about not running them at all (or on opt-in) is it also mitigates some of the danger in update lagging. It seems a majority of the time when I touch someone else's computer they have an adobe product that's out of date and being actively exploited (on the internet) - even if they appear to try to keep up to date with the patches.