Adobe Issues Emergency Patch For Flash Zero-Day Under Attack

JM Safe

Level 39
Thread author
Verified
Top Poster
Apr 12, 2015
2,882
19,912
3,798
Europe
Adobe released an out-of-band security update on Monday to address multiple vulnerabilities rated as critical in its Flash Player, including one (CVE-2015-8651) that is currently being exploited in targeted attacks.

The software maker said the vulnerabilities affect all platforms and could allow an attacker to take control of an affected system.

Adobe provided the following details on the vulnerabilities in a security bulletin posted Monday afternoon:

• These updates resolve a type confusion vulnerability that could lead to code execution (CVE-2015-8644).

• These updates resolve an integer overflow vulnerability that could lead to code execution (CVE-2015-8651).

• These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, CVE-2015-8650).

• These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2015-8459, CVE-2015-8460, CVE-2015-8636, CVE-2015-8645).

Adobe did not provide details on the attacks exploiting CVE-2015-8651, other than describing them as “limited, targeted attacks”.

A company spokesperson told SecurityWeek that the attacks appear to be limited to a spear phishing campaign at this point.

Users should update their products to the latest version using the instructions referenced in the security bulletin.

Several individuals and organizations were credited with reporting the relevant issues and for working with Adobe on the issue.

In early December, Adobe encouraged content creators to build content using new Web standards such as HTML5, but did not mention anything about discontinuing Flash, which has been extremely vulnerable and exploited in many high profile attacks via 0days, as well as commodity attacks leveraging popular exploit kits.

adobe_patch-680x400.jpg


Thank you all for reading! ;)

Source: HERE
 
When will people stop using adobe flash player?
It has been giving security problems for years.Good way to spread ransomware.
They are fixing security issues all the time...for nothing because they will find new critical issues everyday
Well I use mozilla without flash player...HTML5 FTW
Sorry bad english
 
That's why I've uninstalled Silverlight, Shockwave and all Flash Players - If you use Chrome it has Flash built in (no need to install Flash) download Microsoft EMET, Malwarebytes Anti-Exploit or HitmanPro. Alert to prevent Flash in the browser attacks, you will be protected (alongside and antivirus and firewall) :)
 
When will people stop using adobe flash player?
Flash Player comes integrated into Windows 8, 8.1 and 10, so consequently, by default Internet Explorer and Edge can use Flash. This is why it's important to NOT disable Windows Updates.

Google Chrome has their own named Pepper Flash Player and is very secure, you can read that here:
Chromium Blog: The road to safer, more stable, and flashier Flash
Source: PepperFlashPlayer - Debian Wiki

Pepper Flash Player is maintained by Google, and is newer than Adobe Flash Player. Adobe currently still provides security fixes for Adobe Flash Player. Google provides newer features in Pepper Flash Player. Pepper Flash Player can currently only be used with Chromium (and with Chrome).

Recommended: How to Protect Yourself from All These Adobe Flash 0-Day Security Holes
 
  • Like
Reactions: Der.Reisende
Flash Player comes integrated into Windows 8, 8.1 and 10, so consequently, by default Internet Explorer and Edge can use Flash. This is why it's important to NOT disable Windows Updates.

Google Chrome has their own named Pepper Flash Player and is very secure, you can read that here:
Chromium Blog: The road to safer, more stable, and flashier Flash


Recommended: How to Protect Yourself from All These Adobe Flash 0-Day Security Holes
Very interesting, thank you very much!
@Anti-Malware-Reviewer: HMP.A is running at both computers I employ :)
 
  • Like
Reactions: JM Safe and frogboy

You may also like...