Adobe to patch again critical Flash Player vulnerability

kev216

Level 21
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 6, 2014
1,044
12,689
1,988
Belgium
Adobe is expected to release a security update as early as April 7 to fix a critical vulnerability (CVE-2016-1019) in Adobe Flash Player 21.0.0.197 and earlier that “could cause a crash and potentially allow an attacker to take control of an affected system.”

In a Tuesday security advisory, the company said it “is aware” of the vulnerability, which affects Windows, Macintosh, Linux, and Chrome OS versions, “being actively exploited on systems running Windows 7 and Windows XP with Flash Player version 20.0.0.306 and earlier.” Adobe urged users to update to a current version of Flash Player that includes a mitigation introduced in the March 10 Flash Player 21.0.0.182 update that will prevent attackers from exploiting the vulnerability.

Adobe credited researcher Kafeine (EmergingThreats/Proofpoint) as well as Genwei Jiang of FireEye, Inc. and Google's Clement Lecigne for reporting the vulnerability.
 
Lot's of popular sites are slightly moving to upgrade to HTML5, but as it is now, I can't uninstall Flash Player at all. Too much sites that I use or have to use still rely on it.
 
If each one of us is not aware that Flash has certainly many exploitable flaws also in this latest version, which are still unknown to Adobe and we can conclude because of the past history repeats itself and if we assume that the attackers do not succeed tomorrow, to find out in the latest version of Flash a bug exploitable from remote, implement it as a exploit.....then you can install Flash........
 

You may also like...