Shocker: Adobe patches critical Shockwave remote hijack hole

Status
Not open for further replies.
L

LabZero

Thread author
Why not just add 'Patch Adobe' to your to-do list. Every day for the forseeable future

Adobe has patched a critical vulnerability in the Shockwave player that could compromise hundreds of millions of machines.

The company brags that some 450 million users run the vulnerable platform and should manually update through the Adobe website.

The memory corruption hole (CVE-2015-7649) allows attackers to compromise Windows and Mac boxes and gain remote code execution.

Adobe says Fortinet reported the hole, which is rated critical.

"This update addresses a critical vulnerability that could potentially allow an attacker to take control of the affected system," says.

Those running the latest version 12.2.0.162 and earlier will need to upgrade to 12.2.1.171.

The new bug comes after Adobe released a monthly batch of security updates and an emergency critical patch for Flash.

Those holes caused remote-code execution, information disclosure, and crashes across most browsers, platforms, and devices. ®
 
  • Like
Reactions: upnorth and frogboy
L

LabZero

Thread author
Well, the informed users, or those who have a sense of security, know to update browser/plug-in or avoid using these plug-in if they are not needed.
I wonder how many people know these things and they are up-to-date on these security news.
Security is an "optional".... unfortunately for many people.
 
  • Like
Reactions: frogboy

frogboy

In memoriam 1961-2018
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
I know i am always up-to-date or at least to within a few hours anyway. ;)
 
  • Like
Reactions: LabZero

Kalimirro

Level 2
Verified
Nov 29, 2013
56
Adobe vulnerabilities are a major security issue for users worldwide, I have 0 adobe products in my PC or laptope.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Adobe Shockwave usually bundled on those computers (OEM) and sometimes its totally an old version so numbers isn't surprise why vulnerabilities are connected instantly.
 
  • Like
Reactions: soccer97

soccer97

Level 11
Verified
May 22, 2014
517
Adobe Shockwave usually bundled on those computers (OEM) and sometimes its totally an old version so numbers isn't surprise why vulnerabilities are connected instantly.
I ordered an HP laptop (out of service now) that was probably 2 years behind in Java updates, as well as Shockwave updates. I think one of them still had Macromedia instead of Adobe as their name (Before flash 9).

Point is: Many times users may already be 2 years behind or more in those really critical updates right out of the box. I would imagine that the Christmas surprise or excitement would overpower realizing the versions of software most exploited were unpatched (we are all human).

Maybe one day, less Bloatware will be standard (but the prices won't jump up too high). Throw in a copy of just the Original Clean OS (Windows 7, 8, 10 on an official USB or DVD in the box) and it's near perfect. It would save hours. :)
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Maybe one day, less Bloatware will be standard (but the prices won't jump up too high).

Indeed but some manufacturers provides enough bundled program yet useful like for HP products compare to Toshiba.

Still a practical to purchase a machine with OS included as you can save more bucks unlike separate one by most majority consumers.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top