Adobe has released Version 30.0.0.113 of Adobe Flash Player. The update address critical vulnerabilities that could lead to remote code execution affecting version 29.0.0.171 and earlier.
Release date: June 7, 2018
Vulnerability identifier: APSB18-19
Platform: Windows, Macintosh, Linux and Chrome OS
Vulnerability details
Vulnerability Category | Vulnerability Impact | Severity | CVE Number |
Type Confusion | Arbitrary Code Execution | Critical | CVE-2018-4945 |
Integer Overflow | Information Disclosure | Important | CVE-2018-5000 |
Out-of-bounds read | Information Disclosure | Important | CVE-2018-5001 |
Stack-based buffer overflow | Arbitrary Code Execution | Critical | CVE-2018-5002 |
Note that exploit for CVE-2018-5002 exists in the wild, and is being used in limited, targeted attacks against Windows users. These attacks leverage Office documents with embedded malicious Flash Player content distributed via email.
Note: Microsoft has issued an out-of-band update for the critical Adobe Flash Player vulnerabilities: Security update for Adobe Flash Player: June 7, 2018
Update:
- With the option to 'Allow Adobe to install updates', the update will be automatic. Without that setting enabled, either install the update via the update mechanism when prompted or via the Download Center*.
- Windows 7 and earlier: Installation links for Windows 7 and earlier are provided by Adobe at Installation problems | Flash Player | Windows 7 and earlier:
- Flash Player for Internet Explorer - ActiveX
- Flash Player for Firefox/Pale Moon - NPAPI
- Flash Player for Opera and Chromium-based browsers - PPAPI
- Microsoft Edge and Internet Explorer 11: Adobe Flash Player will be automatically updated to the latest version for Windows 8.1 and 10.
- Google Chrome: Adobe Flash Player will be automatically updated to the latest Google Chrome version.
- Flash Player Uninstaller: http://download.macromedia.com/get/flashplayer/current/support/uninstall_flash_player.exe
- Adobe AIR: Adobe - Adobe AIR
*Important Note: Downloading the update from the Adobe Flash Player Download Center link includes a pre-checked option to install unnecessary extras, such as McAfee Scan Plus or Google Drive. If you use the download center, uncheck any unnecessary extras that you do not want. They are not needed for the Flash Player update.
Verify Installation
To verify the Adobe Flash Player version number installed on your computer, go to the About Flash Player page, or right-click on content running in Flash Player and select "About Adobe Flash Player" from the menu.Do this for each browser installed on your computer.
To verify the version of Adobe Flash Player for Android, go to Settings > Applications > Manage Applications > Adobe Flash Player x.x.
References
- Adobe Priority Ratings
- AIR Download Center
- Installing and Updating Flash Player - FAQ
- Release Notes: Flash Player® 30 AIR® 30
- Security Bulletin
- PSIRT
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
No comments:
Post a Comment
Neither spam nor comments containing vulgarities will be approved.