Flash to get update for zero-day bug

Share this article:

UPDATE: The patches are now live

Adobe on Wednesday plans to release an update to its Flash Player to patch a number of vulnerabilities, including one that is being actively exploited.

The update to Flash 10.3.183.7 and earlier versions for Windows, Macintosh, Linux and Solaris is expected to include several fixes.

But the primary reason for the emergency update is to resolve a flaw, rated "important," that is being leveraged in ongoing, targeted attacks in which adversaries are attempting to trick users into clicking on a malicious link contained in an email, according to Adobe. A successful exploit could lead to a cross-site scripting attack by which criminals could take website actions on the victim's behalf.

Wednesday's planned release, which also will bring Flash 10.3.186.6 for Android up to date, includes fixes for a number of other vulnerabilities – these rated "critical" – but none are being actively used in attacks. However, a successful exploit could result in a full system takeover.

The updates are due in the early evening EST. Google, meanwhile, already has fixed the issue in the latest version of Chrome.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

Information sharing requires breaking down barriers, White House cyber guru says

Information sharing requires breaking down barriers, White House ...

The White House has advanced an agenda to promote and facilitate information sharing on security threats and vulnerabilities.

Worm variant of Android ransomware, Koler, spreads via SMS

Worm variant of Android ransomware, Koler, spreads via ...

Upon infection, the Koler variant will send an SMS message to all contacts in the device's address book.

Patch for Windows flaw can be bypassed, prompts temporary fix from Microsoft

Patch for Windows flaw can be bypassed, prompts ...

The Windows zero-day received a patch last week, but the fix can still be bypassed by crafty attackers.