HomeSecurityFlash Player 16.0.0.305 security update fixes zero-day

Flash Player 16.0.0.305 security update fixes zero-day

Adobe has started pushing out a new version of Flash Player that fixes a recently exploited zero-day vulnerability reported by the company last Monday.

Flash Player 16-0-0-305
The vulnerability was designated as CVE-2015-0313 and was exploited by attackers with the Hanjuan exploit kit in malicious campaigns on popular websites such as Dailymotion.

It was reported by Peter Pi of Trend Micro, and was exploited by cybercriminals against users who use Internet Explorer and Mozilla Firefox to browse the web, regardless of the version of the Windows operating system.

Security researchers at Trustwave analyzed the zero-day vulnerability and concluded that it is a use-after-free “caused by a bug in the way Flash handles the FlashCC (formerly Flash Alchemy) 'fast memory access' (domainMemory) function, when the latter is used by Flash Workers (Flash Threads).”

The flaw affects Flash Player 16.0.0.296 and earlier versions for Windows and Macintosh, as well as build 13.0.0.264 and earlier 13.x. versions of the application.

On Wednesday, Adobe updated the initial security bulletin for CVE-2015-0313, announcing that the new update (16.0.0.305) will be delivered automatically where the automatic update mechanism is enabled.

Plug-ins for Internet Explorer 10 and 11 and Google Chromewill be delivered automatically through the appropriate mechanisms from the web browsers.

The download for the desktop version of Flash Player 16.0.0.305 is available from AdobeUsers can download the latest version of Flash Player from Softpedia for Windows and Mac.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS