HomeSecurityEmergency Patch arrives today in Adobe Flash to fix new bug

Emergency Patch Comes to Adobe Flash Today to Fix New Bug

Adobe is trying to raise awareness about a Flash security flaw scheduled for release today, a vulnerability that the company claims is actively exploitable in real-world attacks.

The bug (CVE-2016-1019) affects Adobe Flash Player from version 21.0.0.197 and back and runs on all platforms: Chrome OS, Linux, Mac, and Windows.

Emergency Patch Comes to Adobe Flash Today to Fix New Bug

According to Adobe, successful exploitation of CVE-2016-1019 could lead to a system crash that could potentially allow a hacker to execute code on targeted machines. Depending on the attacker's technical skills and experience, they could leverage the flaw to take control of the devices.

Current information reveals that this vulnerability has already been exploited on Windows XP and Windows 7 computers running Adobe Flash Player 20.0.0.306 and earlier.

Adobe says that security mitigations introduced in Flash Player 21.0.0.182 make exploitation of this bug impossible on computers running recent versions of Flash, but the vulnerability still exists in the Flash Player source code. The company plans to patch this issue with today's release.

Adobe has paid three researchers to discover this flaw. They are: Kafeine (EmergingThreats / Proofpoint), Genwei Jiang (FireEye, Inc.), and Clement Lecigne (Google, Inc.).

It is highly recommended that users always run the latest version of Adobe Flash Player. Additionally, to avoid any problems, Web browsers can automatically block the execution of Flash code and allow the user to decide on a per-page basis where it is allowed. This method ensures that Flash code is only executed on trusted websites, where there is a lower (but not zero) chance of encountering malicious content.

While there are many hopes for the “Flash ,” the technology is too widespread to be completely removed. While modern technologies can successfully replace all of Flash’s benefits, the technology is still essential in older, legacy systems, typically found in government or corporate networks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS