Adobe has released Version 28.0.0.161 of Adobe Flash Player. These updates address critical vulnerabilities that could lead to remote code execution in Adobe Flash Player 28.0.0.137 and earlier versions. Successful exploitation could potentially allow an attacker to take control of the affected system.
In particular, the update addresses CVE-2018-4878 which exists in the wild, and is being used in limited, targeted attacks against Windows users. These attacks leverage Office documents with embedded malicious Flash content distributed via email. Also included in the update are functional fixes.
Release date: February 6, 2018
Vulnerability identifier: APSB18--03
Platform: Windows, Macintosh, Linux and Chrome OS