There is critical vulnerability in Adobe Flash Player 10.0.45.2 and earlier for Windows, Mac, and Linux/Unix variants, as well as the authplay.dll component in Adobe Reader and Acrobat 9.x versions for Windows, Mac, and *nix operating systems. There are reports that this vulnerability is being actively exploited in the wild against Flash Player, Adobe Reader, and Acrobat.
Mitigations:
[UPDATE] Flash Player: Adobe Security Bulletin APSB10-14 recommends updating to Flash Player 10.1.53.64 or 9.0.277.0 and AIR to 2.0.2.12610. This will update the Flash web browser plug-in and ActiveX control and AIR, but will not update Flash support in Adobe Reader, Acrobat, or other products.
Acrobat and Adobe Reader: Delete authplay.dll.
This file is typically located in:
C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll (for Reader)
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\authplay.dll (for Acrobat)
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\authplay.dll (for Reader on 64-bit systems)
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\authplay.dll (for Acrobat on 64-bit systems)
For more information, please visit these websites:
http://www.adobe.com/support/security/advisories/apsa10-01.html
http://community.ca.com/blogs/securityadvisor/archive/2010/06/06/zero-day-attack-in-adobe-products.aspx
