Adobe Acrobat, Reader, and Flash Player Remote Code Execution Vulnerability
Adobe Acrobat, Reader, and Flash Player are prone to a remote code-execution vulnerability.
An attacker can exploit this issue by supplying a malicious Flash ('.swf') file or by embedding a malicious Flash application in a PDF file. Successful exploits may allow the attacker to execute arbitrary code in the context of the user running the affected application. Failed attempts will likely result in denial-of-service conditions.
UPDATE (September 4, 2009): Mac OS X 10.6 reportedly ships with Flash Player 10.0.23.1, which will overwrite any installed version of Flash Player when Mac OS X is being installed.
The issue affects the following:
Reader and Acrobat 9.1.2
Flash Player 9 and 10