While many security experts say Adobe should stop releasing Flash and save us all from this burden, the company seems to be sticking to its decision to support Flash. So yesterday it issued yet another security update, now patching 12 critical vulnerabilities this month.
The update arrived just in time, on the same day that Microsoft released security updates for its products.
Considering that Adobe has classified the recent patch as "Priority 1" and "Critical", this is a "must update" version of Flash, which users should not delay installing.
This month's heroes are security researchers from companies like Tencent, Palo Alto Networks, COSIG, CloverSec Labs, and Trend Micro, who took the time to report on Flash vulnerabilities.
Eleven of the twelve vulnerabilities that Adobe fixed this month led to remote code execution on the user's computer, which could potentially allow an attacker to take control of the compromised system.
Adobe patched a type confusion vulnerability (CVE-2016-6992), use-after-free vulnerabilities (CVE-2016-6981, CVE-2016-6987), and memory corruption issues (CVE-2016-4273, CVE-2016-6982, CVE-2016-6983, CVE-2016-6984, CVE-2016-6985, CVE-2016-6986, CVE-2016-6989, CVE-2016-6990). The twelfth issue was a Flash security bypass (CVE-2016-4286), which is also something users will want to avoid.
There is no information indicating that these vulnerabilities have been used in live attacks before Adobe's October patch.
Updates for Flash, which runs on Windows, Mac , and Linux, have been released and are available for download. The latest version of Adobe Flash Player is 23.0.0.185 for Windows and Mac, and 11.2.202.637 for Linux distros.
In addition to Flash Player, other Adobe products received security patches. The list includes Adobe's Creative Cloud Desktop Application and Adobe Acrobat and Reader.
For Creative Cloud Desktop Application, Adobe has fixed CVE-2016-6935, which is a low priority issue that resolves an unquoted vulnerability in the search path. Adobe says an attacker could exploit this flaw to achieve local privilege escalation and gain additional privileges.
The company's engineers focused more on the Adobe Acrobat and Reader applications, where they fixed 71 security flaws ranging from bypassing restrictions to remote code execution.

