Submission + - No javascript needed for new Adobe exploits (cnet.com)
bl8n8r writes: More woes for Adobe as security firm creates proof of concept attack which injects malicious code as part of the update process. The user only needs to click a dialog box to execute the code and no javascript is needed to launch the exploit. The exploit affects Foxit as well as Adobe Acrobat software. This exploit is made possible through the host software allowing execution of system binaries. Not clear if it's multiplatform, but seems plausible.