Affiliate Disclosure
If you buy through our links, we may get a commission. Read our ethics policy.

Adobe acknowledges critical remote vulnerability in Flash, exploits already in the wild

Adobe on Saturday released an updated version of its Flash player software that patches an undisclosed vulnerability which could allow remote attackers to take control of Macs or PCs, urging users to update as the problem is being actively exploited by malicious actors.

Flash versions up to and including 16.0.0.287 on OS X and Windows and 11.2.202.438 on Linux are susceptible to the attack, the cause of which has yet to be detailed. Mac users with Adobe's automatic update feature enabled should begin receiving updates to version 16.0.0.296 immediately, and the company is preparing a standalone patch for manual installation to be released this week. Adobe is also working with Google to update the embedded version of Flash included in the Chrome browser.

The vulnerability —  which has been assigned CVE number 2015-0311 —  is "being actively exploited in the wild via drive-by-download attacks against systems running Internet Explorer and Firefox on Windows 8.1 and below," Adobe said in a security advisory. A "drive-by-download" attack is one in which software is downloaded to a user's computer without their knowledge or explicit consent.

Adobe defines CVE-2015-0311 as "critical," meaning a "vulnerability, which, if exploited would allow malicious native-code to execute, potentially without a user being aware."

Users can check the version of Flash installed on their system by visiting Adobe's About Flash Player page or right-clicking on Flash content in their browser and choosing "About Adobe (or Macromedia) Flash Player" from the contextual menu. Instructions for enabling automatic updates or manually updating Flash can be found here.



94 Comments

๐ŸŽ„
sleakaj 10 Years · 32 comments

Every single day, Flash becomes more and more irrelevant. I dumped Flash from my system some time ago and I'm better off. The death of Flash couldn't come soon enough.

๐ŸŽ…
monstrosity 17 Years · 2227 comments

I wish Flash would just hurry up and die. I blame Google for it's continued existence.

๐ŸŽ
pjwilkin 12 Years · 74 comments

Quote:
Originally Posted by monstrosity 
 

I wish Flash would just hurry up and die. I blame Google for it's continued existence.


I blame Microsoft, especially as it's now a system component in Windows 8, 8.1 and 10

๐Ÿช
dacloo 20 Years · 814 comments

Seriously? Wow what a weird decision. Love to read more about the subject. [quote name="PJWilkin" url="/t/184492/adobe-acknowledges-critical-remote-vulnerability-in-flash-exploits-already-in-the-wild#post_2666199"] I blame Microsoft, especially as it's now a system component in Windows 8, 8.1 and 10 [/quote]

๐ŸŽ…
pjwilkin 12 Years · 74 comments


It's available via Windows Update on Windows 8, 8.1 and 10 

 

EG from a quick google http://support2.microsoft.com/kb/2999249

 

I can see why MS decided to ship it with Windows (so at least it gets patched), but they should have just let it die