Security Advisory for Adobe Flash Player April 6, 2016

  • 7 April 2016
  • 2 replies
  • 370 views

Userlevel 7
Badge +56

Security Advisory for Adobe Flash Player


Release date: April 5, 2016
Last updated: April 6, 2016
Vulnerability identifier: APSA16-01
CVE number: CVE-2016-1019
Platforms: Windows, Macintosh, Linux and Chrome OS

Summary


A critical vulnerability (CVE-2016-1019) exists in Adobe Flash Player 21.0.0.197 and earlier versions for Windows, Macintosh, Linux, and Chrome OS. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.
Adobe is aware of reports that CVE-2016-1019 is being actively exploited on systems running Windows 10 and earlier with Flash Player version 20.0.0.306 and earlier. A mitigation introduced in Flash Player 21.0.0.182 currently prevents exploitation of this vulnerability, protecting users running Flash Player 21.0.0.182 and later.
 
https://helpx.adobe.com/security/products/flash-player/apsa16-01.html
 

UPDATED: Security Advisory posted for Adobe Flash Player (APSA16-01)

A Security Advisory (APSA16-01) has been published regarding a critical vulnerability (CVE-2016-1019) in Adobe Flash Player.  UPDATE: Adobe is aware of reports that CVE-2016-1019 is being actively exploited on systems running Windows 7 and Windows XP Windows 10 and earlier with Flash Player version 20.0.0.306 and earlier.  A mitigation introduced in Flash Player 21.0.0.182 currently prevents exploitation of this vulnerability, protecting users running Flash Player 21.0.0.182 and later.
Adobe is planning to provide a security update to address this vulnerability as early as April 7.  For the latest information, users may continue to monitor the Adobe Product Security Incident Response Team blog.
 
http://blogs.adobe.com/psirt/?p=1330
 
Daniel 😉

2 replies

Userlevel 7
Badge +62
Much appreciated Daniel!  ;)
Userlevel 7
Cheers, Daniel...good to know, and thanks for providingthe heads up...as usual. ;)

Reply