Adobe has released a new version of Flash Player, patching a total of nine security vulnerabilities from the previous version, most of which pose the risk of a potential attack through arbitrary code execution.
Three of the vulnerabilities (CVE-2015-0303, CVE-2015-0.305, and CVE-2015-0308) were discovered by Google security researchers, who recently uncovered two elevation of privilege in Windows 8.1, before Microsoft was allowed to issue fixes through monthly security updates.
In Flash Player, they identified memory corruption, use-after-free , and type confusion bugs, which could allow code execution if successfully exploited.
The additional security updates fix bugs such as incorrect file validation (CVE-2015-0301), heap-based buffer overflow (CVE-2015-0304 and CVE-2015-0309), and an out-of-bounds read vulnerability that could be exploited to leak memory (CVE-2015-0307).
According to a security bulletin from Adobeon Tuesday, the update resolves an information disclosure vulnerability that posed a risk of keystroke logging (CVE-2015-0302).
The Flash Player (16.0.0.257) update is happening automatically in Internet Explorer and Google Chrome. The update may also be installed automatically on systems with automatic updates enabled.

