Adobe has released Version 28.0.0.161 of Adobe Flash Player. These updates address critical vulnerabilities that could lead to remote code execution in Adobe Flash Player 28.0.0.137 and earlier versions. Successful exploitation could potentially allow an attacker to take control of the affected system.
In particular, the update addresses CVE-2018-4878 which exists in the wild, and is being used in limited, targeted attacks against Windows users. These attacks leverage Office documents with embedded malicious Flash content distributed via email. Also included in the update are functional fixes.
Release date: February 6, 2018
Vulnerability identifier: APSB18--03
Platform: Windows, Macintosh, Linux and Chrome OS
Update:
Security Bulletin
Flash Player® 28 AIR® 28
In particular, the update addresses CVE-2018-4878 which exists in the wild, and is being used in limited, targeted attacks against Windows users. These attacks leverage Office documents with embedded malicious Flash content distributed via email. Also included in the update are functional fixes.
Release date: February 6, 2018
Vulnerability identifier: APSB18--03
Platform: Windows, Macintosh, Linux and Chrome OS
Update:
- With the option to 'Allow Adobe to install updates', the update will be automatic. Without that setting enabled, either install the update via the update mechanism when prompted or via the Download Center*.
- Windows 7 and earlier: Installation links for Windows 7 and earlier are provided by Adobe at Installation problems | Flash Player | Windows 7 and earlier:
- Microsoft Edge and Internet Explorer 11: Adobe Flash Player will be automatically updated to the latest version for Windows 8.1 and 10.
- Google Chrome: Adobe Flash Player will be automatically updated to the latest Google Chrome version.
- Flash Player Uninstaller: http://download.macromedia.com/get/flashplayer/current/support/uninstall_flash_player.exe
- Adobe AIR: Adobe - Adobe AIR
Security Bulletin
Flash Player® 28 AIR® 28
Last edited: