Arthur Posted January 22, 2015 Posted January 22, 2015 (edited) Expect another update to follow this one since v16.0.0.287 doesn't include a fix for the recently discovered zero-day vulnerability. Edit. The release notes mention Adobe have "updated Flash Player with a critical security fix". It doesn't say what for and there isn't anything on their security bulletin webpage. Release Notes / Security Bulletin / Admin Guide [b]Internet Explorer[/b] http://fpdownload.macromedia.com/get/flashplayer/pdc/16.0.0.287/install_flash_player_ax.exe [b]Plug-in based browsers[/b] (Firefox, Opera etc.) http://fpdownload.macromedia.com/get/flashplayer/pdc/16.0.0.287/install_flash_player.exe [b]Uninstaller[/b] http://download.macromedia.com/get/flashplayer/current/support/uninstall_flash_player.exe [b]Standalone Projector[/b] http://download.macromedia.com/get/flashplayer/updaters/16/flashplayer_16_sa.exe [b]Mac OS X[/b] http://fpdownload.macromedia.com/get/flashplayer/pdc/16.0.0.287/install_flash_player_osx.dmg [b]Android v4.x[/b] http://download.macromedia.com/pub/flashplayer/installers/archive/android/11.1.115.81/install_flash_player_ics.apk https://play.google.com/store/apps/details?id=com.adobe.flashplayer [b]Android v2.x / v3.x[/b] http://download.macromedia.com/pub/flashplayer/installers/archive/android/11.1.111.73/install_flash_player_pre_ics.apk MSIs can be downloaded from Adobe if you have a distribution agreement. The links above are the PUBLIC download links. Edited January 22, 2015 by Arthur 3
Arthur Posted January 22, 2015 Author Posted January 22, 2015 http://krebsonsecurity.com/2015/01/flash-patch-targets-zero-day-exploit While Flash users should definitely update as soon as possible, there are indications that this fix may not plug all of the holes in Flash for which attackers have developed exploits. In a statement released along with the Flash update today, Adobe said its patch addresses a newly discovered vulnerability that is being actively exploited, but that there appears to be another active attack this patch doesn’t address. “Adobe is aware of reports that an exploit for CVE-2015-0310 exists in the wild, which is being used in attacks against older versions of Flash Player,” Adobe said. “Additionally, we are investigating reports that a separate exploit for Flash Player 16.0.0.287 and earlier also exists in the wild.”
Arthur Posted January 23, 2015 Author Posted January 23, 2015 16.0.0.287 is being exploited so there's going to be yet another update. http://blogs.adobe.com/psirt/?p=1160 A Security Advisory (APSA15-01) has been published regarding a critical vulnerability (CVE-2015-0311) in Adobe Flash Player 16.0.0.287 and earlier versions for Windows, Macintosh and Linux. We are aware of reports that this vulnerability is being actively exploited in the wild via drive-by-download attacks against systems running Internet Explorer and Firefox on Windows 8 and below. Adobe expects to have a patch available for CVE-2015-0311 during the week of 26 January.
Arthur Posted January 24, 2015 Author Posted January 24, 2015 The following blog post describes what happens after you get infected with the malware exploiting the current vulnerability in Flash Player. Unpatched Vulnerability (zero day) in Flash Player is being exploited by Angler EK tl;dr. Google Chrome users are safe (at least for the moment). EMET 5.1 may help mitigate/prevent the exploit if you use Internet Explorer.
Arthur Posted January 25, 2015 Author Posted January 25, 2015 (edited) Flash Player v16.0.0.296 has been released. MSIs are available from the usual place. Although Adobe's website still shows v16.0.0.287 as the latest, the downloads themselves are v16.0.0.296. Edited January 25, 2015 by Arthur
kennysarmy Posted January 27, 2015 Posted January 27, 2015 Flash Player v16.0.0.296 has been released. MSIs are available from the usual place. Although Adobe's website still shows v16.0.0.287 as the latest, the downloads themselves are v16.0.0.296. it's never ending....
Arthur Posted February 2, 2015 Author Posted February 2, 2015 it's never ending.... There's another update due this week. http://helpx.adobe.com/security/products/flash-player/apsa15-02.html A critical vulnerability (CVE-2015-0313) exists in Adobe Flash Player 16.0.0.296 and earlier versions for Windows and Macintosh. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system. We are aware of reports that this vulnerability is being actively exploited in the wild via drive-by-download attacks against systems running Internet Explorer and Firefox on Windows 8.1 and below. Adobe expects to release an update for Flash Player during the week of 2 February. 1
X-13 Posted February 3, 2015 Posted February 3, 2015 (edited) Is anyone doing the updates through SCUP? Currently looking into it, may take some of the hassle away... Le EDIT: Oh, God... why wasn't I using this before?! It's so beautiful... It's just a shame I can't push them into WSUS... Edited February 3, 2015 by X-13
Arthur Posted February 5, 2015 Author Posted February 5, 2015 :mad::mad::mad::mad::mad::mad::mad: Flash Player 16.0.0.305 is now available.
Norphy Posted February 5, 2015 Posted February 5, 2015 Flash Player 16.0.0.305 is now available. Not showing on the Flash distribution page for me yet.
Arthur Posted February 5, 2015 Author Posted February 5, 2015 It is for me. The MSIs have been updated even if the webpage hasn't been.
X-13 Posted February 5, 2015 Posted February 5, 2015 Not showing on the Flash distribution page for me yet. this fing wot I said before Seriously... This seems awesome. It's picking up the update and it's ready to push out with WSUS. [i think... Not too up to speed with it yet.]
sonofsanta Posted February 6, 2015 Posted February 6, 2015 fnnnaaaaarrrgghh Downloaded it yesterday when the web page updated to show version .305. Except the MSI was still bloomin' 296 (as you only find out if you think to look inside the MSI with 7zip, because the file is just "16"), and I've just wasted no end of time trying to work out wth was going on with my SCCM deployment and why it was uninstalling 296 only to reinstall 296 when it's normally such an easy job. MSI download is correct now, but Odin's beard, are Adobe deliberately trying to annoy me now or something.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now