Patch your Flash Player now! Zero-day actively exploited in the wild

Adobe has released patches for all users running Flash Player 29.0.0.171 and earlier versions, addressing critical flaws in its trouble-plagued platform.

Whether you are running the software on Windows, macOS, Linux or Chrome OS, the Flash Player creators urge you to install the newest version immediately!

“Adobe is aware of a report that an exploit for CVE-2018-5002 exists in the wild, and is being used in limited, targeted attacks against Windows users. These attacks leverage Office documents with embedded malicious Flash Player content distributed via email,” the company says in its advisory.

Affected installments of Flash include Adobe Flash Player Desktop Runtime, Adobe Flash Player for Google Chrome, and Adobe Flash Player for Microsoft Edge and Internet Explorer 11. Exploitation of the flaw can lead to arbitrary code execution, says Adobe.

Users of Flash Player Desktop Runtime must install version 30.0.0.113 via the update mechanism within the product. The procedure applies to all desktop users, regardless of their OS. The next version of Chrome to be released by Google will include Flash Player 30.0.0.113 by default. The same goes for the Flash plugins in Microsoft Edge and Internet Explorer 11 for Windows 10.

The downloadable patches can be found at the Adobe Flash Player Download Center.

*** This is a Security Bloggers Network syndicated blog from HOTforSecurity authored by Filip Truta. Read the original post at: https://hotforsecurity.bitdefender.com/blog/patch-your-flash-player-now-zero-day-actively-exploited-in-the-wild-20003.html

Recent Posts

VMRay Closes $25 Million Series B

Digital+ Partners Leads Continuation Funding Round in Growing Automated Threat Analysis & Detection Provider, Closing its Series B Round at…

2 hours ago

The Hacker Mind Podcast: Hacking OpenWRT

For three years OpenWRT had a severe validation problem with its download package manager, until a fuzz tester found and…

2 hours ago

Goodbye to Flash – if you’re still running it, uninstall Flash Player now

It’s time to say a final “Goodbye” to Flash. (Or should that be “Good riddance”?) With earlier this week seeing…

2 hours ago

Smart DNS: Delivering the Best Subscriber Experience

This is the second in a series of blog posts that discuss how smart DNS resolvers can enhance ongoing network…

3 hours ago

New Microsoft Spear-Phishing Attack Uses Exact Domain Spoofing Tactic

Security researchers detected a new spear-phishing attack that’s using an exact domain spoofing tactic in order to impersonate Microsoft. On…

5 hours ago

6 ways to use analytics to deliver an exceptional end-user experience: Part 3

Welcome back to the last part of our three-part blog series on how to leverage analytics to deliver an exceptional…

5 hours ago