Adobe has started pushing out a new version of Flash Player that fixes a recently exploited zero-day vulnerability reported by the company last Monday.

The vulnerability was designated as CVE-2015-0313 and was exploited by attackers with the Hanjuan exploit kit in malicious campaigns on popular websites such as Dailymotion.
It was reported by Peter Pi of Trend Micro, and was exploited by cybercriminals against users who use Internet Explorer and Mozilla Firefox to browse the web, regardless of the version of the Windows operating system.
Security researchers at Trustwave analyzed the zero-day vulnerability and concluded that it is a use-after-free “caused by a bug in the way Flash handles the FlashCC (formerly Flash Alchemy) 'fast memory access' (domainMemory) function, when the latter is used by Flash Workers (Flash Threads).”
The flaw affects Flash Player 16.0.0.296 and earlier versions for Windows and Macintosh, as well as build 13.0.0.264 and earlier 13.x. versions of the application.
On Wednesday, Adobe updated the initial security bulletin for CVE-2015-0313, announcing that the new update (16.0.0.305) will be delivered automatically where the automatic update mechanism is enabled.
Plug-ins for Internet Explorer 10 and 11 and Google Chromewill be delivered automatically through the appropriate mechanisms from the web browsers.
The download for the desktop version of Flash Player 16.0.0.305 is available from AdobeUsers can download the latest version of Flash Player from Softpedia for Windows and Mac.
