The latest update for Adobe Flash Player (15.0.0.223) includes a total of 18 security fixes, which address critical vulnerabilities. Most of these (15 in number) allow arbitrary code execution on affected computer systems.
Previous versions of the software contain several flaws, which can lead to memory corruption, use-after-free and heap buffer overflow, permission issues, and even information leakage.
Successful exploitation of some of the aforementioned vulnerabilities gives an attacker the ability to gain higher administrative privileges or to obtain access to session tokens.
According to Adobe 's security bulletin , in the case of vulnerabilities with identifiers CVE-2014-8442 and CVE-2014-0583, malicious actors could escalate their privileges on affected systems from low to medium integrity level.
The discovery of the above vulnerabilities was credited to Haifei Li of McAfee Labs IPS Team (CVE-2014-0583), as well as to researchers Behrang Fouladi and Axel Souchet of Microsoft Vulnerability Research.
The increased security of the latest version of Flash Player is also due to researchers from Google's Project Zero (Ian Beer, Natalie Silvanovich, Tavis Ormandy and Chris Evans), as well as researchers from Venustech ADLAB, TrendMicro, and the Chinese company KnowSec.

