Adobe has released a new update for Flash Player for Windows, macOS, Linux, and Chrome OS, addressing multiple critical vulnerabilities.

Last week, the Adobe Security Bulletin revealed that several exploits involving its products are still circulating online.
These exploits target Windows computers and exploit Office documents with embedded Flash Player content distributed via email to infect users. The vulnerabilities affect Adobe Flash Player versions 29.0.0.171 and older.
The patch fixed several vulnerabilities in its program, and the company thanked those who revealed the various security holes as well as those who worked to protect its customers.
Trend Micro reported two of the security vulnerabilities (CVE-2018-5000 and CVE-2018-5001) and in collaboration with Jihui Lu of Tencent KeenLab also reported the vulnerability CVE-2018-4945.
“These are so-called confusion vulnerabilities, which means the code doesn’t properly check the input data,” said Allan Liska, an analyst at Recorded Future. “When you exploit it successfully, it allows remote code execution.”
Another critical vulnerability (CVE-2018-5002), reported by multiple sources, concerns a buffer overflow that also allows remote code execution. This one works through phishing. “The exploit exploits a Flash file embedded in a Microsoft Office document,” Liska said. “When the victim opens the Office document, the code from the Flash Trojan automatically runs and executes a shell code, which communicates with the C&C servers.”
To protect yourself, you should immediately upgrade Adobe Flash and disable macros in Microsoft Office. Adobe also recommends visiting the Adobe Flash Player page to verify which version of Flash is installed on your system.
