Adobe flaw has been used in attacks since early January

24.02.2009

"This developed legs last week," he added in an instant message interview. "I think our blogging the vulnerability and Sourcefire blogging the exploit details got it going."

The vulnerability lies in the way that Adobe opens files that have been formatted using the JBIG data compression algorithm. Adobe the bug by March 11, but in the meantime Sourcefire has also released an that fixes the issue.

Security experts say that users can also mitigate the attack by disabling JavaScript within their Adobe software, but this could break corporate applications that rely on the scripting software.