Adobe has released a security advisory (APSA18-01) for Adobe Flash Player that confirms a critical security vulnerability (original…) that exists in Player version 28.0.0.137 and earlier versions.
Flash Player 28.0.0.137 is the latest version of the application, which means that all installed versions of Flash are affected by the vulnerability.
The affected products:
Adobe Flash Player Desktop Runtime on Windows, Linux, and Mac platforms.
Adobe Flash Player for Google Chrome on Windows, Mac, Linux, and Chrome OS platforms.
Adobe Flash Player for Microsoft Edge and Internet Explorer 11 on Windows 8.1 and 10.
Adobe plans to release an update for Flash Player next week that is supposed to address the security gaps.
The company confirmed that the vulnerability can be exploited on Windows with Office documents that have malicious Flash content embedded. Of course, these documents are distributed via email.
Adobe says that the vulnerability, CVE-2018-4878, is already being exploited in limited and targeted attacks against Windows users.
Adobe also says that anyone who wants to protect themselves should use Protected View to open any Office documents in read-only mode. This is done by going to File – Options and enabling the Protected View options under Trust – Trust Center Settings – Protected View.
All those who use flash, it would be a good idea to disable it from your browser, because the attacks that have been observed may come through Office documents, but that does not mean that they will not evolve into attacks that can also be carried out via the web.
Patience, where will it go? The universal deactivation of Adobe Flash from all web applications is coming, it's just that it's taking a while...
