Jump to content

Adobe Flash Player v18.0.0.160 and AIR v18.0.0.144 released


Recommended Posts

Posted

Apart from the usual security vulnerabilities being fixed, the latest Flash Player update also includes some new functionality. See the second quote below for details.

 

Release Notes / Security Bulletin / Admin Guide / SCUP Catalog / Distribution Agreements (Flash Player, AIR)

 

In today's scheduled release, we've updated Flash Player and AIR with important bug fixes and security updates.

 

These updates address vulnerabilities that could potentially allow an attacker to take control of the affected system.

 

CVE numbers: CVE-2015-3096, CVE-2015-3097, CVE-2015-3098, CVE-2015-3099, CVE-2015-3100, CVE-2015-3101, CVE-2015-3102, CVE-2015-3103, CVE-2015-3104, CVE-2015-3105, CVE-2015-3106, CVE-2015-3107, CVE-2015-3108

 

New Features

 

Improved Flash Player Install Process

We have had consistent feedback from our customers that they prefer not to shut down their browsers to simply install Flash Player. This feature removes this requirement whenever possible. With Flash Player 18, in the vast majority of cases, the installer will no longer display a dialog to shut down the currently running browsers or applications that are using Flash Player!

 

Once the installation is completed, you will be notified that the browser may need to be restarted to use the newly installed version. This requirement depends on your browser’s ability to see the new version. Either way, Flash will continue to work and you can easily force the new version to appear by simply restarting your browser when it’s convenient for you.

 

Audio APIs added to Flash Player NPAPI

We have added the ability for NPAPI-compatible browsers and applications to query the player and detect if audio is currently being played and if it can be muted. This new feature will allow applications to alert the user if audio is being played and give them the ability to mute, even if the Flash content does not.

 

This new API is not applicable to ActionScript developers and is only available to browser and application developers that host the Flash plugin.

 

MSIs for Flash Player can be downloaded from Adobe via the URL they provide once you have signed the distribution agreement. The links below are the PUBLIC download links.

 

[b]Windows[/b]

[b]Internet Explorer[/b]
https://fpdownload.macromedia.com/pub/flashplayer/latest/help/install_flash_player_ax.exe

[b]NPAPI Plug-in based browsers[/b] (Firefox, Opera < 12 etc.)
https://fpdownload.macromedia.com/pub/flashplayer/latest/help/install_flash_player.exe

[b]PPAPI Plug-in based browsers[/b] (Chromium, Opera > 15 etc.)
https://fpdownload.macromedia.com/pub/flashplayer/latest/help/install_flash_player_ppapi.exe

[b]Uninstaller[/b]
http://download.macromedia.com/get/flashplayer/current/support/uninstall_flash_player.exe

[b]Standalone Projector[/b]
http://download.macromedia.com/get/flashplayer/updaters/18/flashplayer_18_sa.exe

 

[b]OS X[/b]
https://fpdownload.macromedia.com/pub/flashplayer/latest/help/install_flash_player_osx.dmg

 

[b]Android v4.x[/b]
http://download.macromedia.com/pub/flashplayer/installers/archive/android/11.1.115.81/install_flash_player_ics.apk
https://play.google.com/store/apps/details?id=com.adobe.flashplayer

[b]Android v2.x / v3.x[/b]
http://download.macromedia.com/pub/flashplayer/installers/archive/android/11.1.111.73/install_flash_player_pre_ics.apk

 

Adobe AIR (Public Download Links)

 

[b]Windows[/b]
http://airdownload.adobe.com/air/win/download/18.0/AdobeAIRInstaller.exe

[b]Mac[/b]
http://airdownload.adobe.com/air/mac/download/18.0/AdobeAIR.dmg

  • Thanks 1
Posted
wonder if the msi for 18 will work 17 just caused me so many issues with not deploying correctly iirc I had to resort to scripting the flash uninstaller then the installer and even then on some pcs I ended up rebuilding as flash just wouldn't work
Posted (edited)

...I just got 17 to deploy.

 

tableflip.jpg

 

Le EDIT: This seems to have gone through with no problems... hmm.

Edited by X-13
  • 2 weeks later...
Posted
Adobe has just released Flash Player v18.0.0.194. :(

 

AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAARRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

Posted (edited)

More details on the exploit fixed by 18.0.0.194.

 

Adobe issues emergency patch for actively exploited Flash vulnerability « MyCE

 

Adobe has issued an emergency patch for a vulnerability in Flash Player that is actively used to infect computers with malware. According to the company the leak is exploited in targeted, but limited attacks in which IE users on Windows 7, Vista and XP are the target and also Firefox users on Windows XP.

 

The leak, that was reported to Adobe by security company FireEye, allows an attacker to execute random code on a computer. Users can be infected by nothing more than visiting a malicious or hacked website or when an infected advertisement is shown to the user. Adobe urgently advises users to install an update to Flash Player 18.0.0.194 within 72 hours.

 

Operation Clandestine Wolf – Adobe Flash Zero-Day in APT3 Phishing Campaign « FireEye Blog

 

The phishing emails used by APT3 during this campaign were extremely generic in nature, almost appearing to be spam. An example email body:

 

Save between $200-450 by purchasing an Apple Certified Refurbished iMac through this link. Refurbished iMacs come with the same 1-year extendable warranty as new iMacs. Supplies are limited, but update frequently.

Don't hesitate . . .>Go to Sale

The string “>Go to Sale” was a link that used the following URL structure:

 

hxxp://..//.html

 

Exploit Details

The attack exploits an unpatched vulnerability in the way Adobe Flash Player parses Flash Video (FLV) files. The exploit uses common vector corruption techniques to bypass Address Space Layout Randomization (ASLR), and uses Return-Oriented Programming (ROP) to bypass Data Execution Prevention (DEP). A neat trick to their ROP technique makes it simpler to exploit and will evade some ROP detection techniques.

 

Shellcode is stored in the packed Adobe Flash Player exploit file alongside a key used for its decryption. The payload is xor encoded and hidden inside an image.

Edited by Arthur
  • 2 weeks later...
Posted

There's another zero-day exploit in the wild for Flash Player. Adobe are going to release an update sometime today.

 

  • Adobe to Patch Hacking Team’s Flash Zero-Day
     
    Adobe Systems Inc. says its plans to issue a patch on Wednesday to fix a zero-day vulnerability in its Flash Player software that is reportedly being exploited in active attacks. The flaw was disclosed publicly over the weekend after hackers broke into and posted online hundreds of gigabytes of data from Hacking Team, a controversial Italian company that’s long been accused of helping repressive regimes spy on dissident groups.
     
    Several reports on Twitter suggested the exploit could be used to bypass Google Chrome‘s protective “sandbox” technology, a security feature that forces the program to run in a heightened security mode designed to block attacks that target vulnerabilities in Flash. A spokesperson for Google confirmed that attackers could evade the Chrome sandbox by using the Flash exploit in tandem with another Windows vulnerability that appears to be unpatched at the moment. Google also says its already in the process of pushing the Flash fix out to Chrome users.
     
  • PSA: Flash Zero-Day Now Active in The Wild
     
    The Neutrino exploit kit is already leveraging the latest Flash zero-day which is still unpatched.
     
    As we were testing various exploit kits throughout the day, the zero-day hit at 3 PM PT with Neutrino. We believe it is the same zero-day as the one revealed in the Hacking Team hack, which we blogged about earlier today.
     
    This is one of the fastest documented case of an immediate weaponization in the wild, possibly thanks to the detailed instructions left by Hacking Team.

 

http://i.imgur.com/K6bVlz3.png

Posted

Microsoft's EMET or Malwarebytes Anti-Exploit would also prevent this exploit from working.

 

https://community.qualys.com/blogs/laws-of-vulnerabilities/2015/07/06/hackingteam-0-day-for-flash

 

Adobe acknowledged the bug in APSA15-03 and will make an update available on Wednesday 8th July. Excellent, quick reaction. Google is credited for reporting the bug now called CVE-2015-5119. Security researcher @kafeine reports that the Angler, Fiddler, Nuclear and Neutrino Exploits Kits have added CVE-2015-5119 to their lineup. Patch as quickly as possible or think about adding EMET to your workstations.

 

EMET 4.1 (last available version for XP) in its default configuration takes care of the attack on Windows XP. EMET is a good additional security tool to install once you are fully patched. It monitors for certain attack patterns and neutralizes them - if the exploit uses any of the common ways to execute shellcode EMET users have a good chance to get away unharmed.

Posted
Oh the joys. Perhaps Adobe could look at actually patching Flash so it can't be exploited in this way? Like, a total re-write. Or better yet, retiring the damn thing.
Posted
Or better yet, retiring the damn thing.

 

You know as well as I do, that if Flash gets retired it will just mean lots of schools using something that will never get updated and will be a massive security flaw.

Posted
Maybe I'd optimistically think that developers would shift their content across to HTML5 instead, thus not needing it at all? Pretty wild thought though, especially with some of the junk content we use.
Posted
Maybe I'd optimistically think that developers would shift their content across to HTML5 instead, thus not needing it at all? Pretty wild thought though, especially with some of the junk content we use.

 

Put it this way, we still use the installed version of the 2simple software, despite the fact that the HTML5 web version does everything the local version does.

 

2simple is literally the only reason I have to mess aboot with flash.

Posted (edited)
taking all bets on when this patch needs a patch im betting by the 16th lol

 

That's far too optimistic! :D

 

Yeah - there'll be another 3 before then :rolleyes:

 

Put it this way, we still use the installed version of the 2simple software, despite the fact that the HTML5 web version does everything the local version does.

 

2simple is literally the only reason I have to mess aboot with flash.

 

2Simple have promised to come and demo that Flash isn't required for Purplemash any more.......

Edited by jmak
Posted
taking all bets on when this patch needs a patch I'm betting by the 16th lol

We were both right! There's another update being released next week. :)

 

Adobe To Fix Another Hacking Team Zero-Day

 

For the second time in a week, Adobe Systems Inc. says it plans fix a zero-day vulnerability in its Flash Player software that came to light after hackers broke into and posted online hundreds of gigabytes of data from Hacking Team, a controversial Italian company that’s long been accused of helping repressive regimes spy on dissident groups.

 

In an advisory published late Friday evening, Adobe said it plans to issue another Flash patch the week of 13 July 2015. “This vulnerability was reported to us following further investigation of the data published after the Hacker Team [sic] data breach,” the advisory notes.

 

Adobe said the flaw is present in the latest version of Flash for Windows, Mac and Linux systems, and that code showing attackers how to exploit this flaw is already available online.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...