Adobe Flash Flaw Gets Zero-Day Fix

Adobe on Wednesday released a security update that fixed seven Flash Player vulnerabilities, including a zero-day cross-site scripting (XSS) flaw found by Google researchers.

The vulnerability, classified as "critical" by Adobe, could allow an attacker to gain access to a user's computer after visiting a malicious e-mail or Web site. Adobe has reported that systems have already been compromised using this flaw.

"There are reports that this vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an e-mail message," said Adobe in a security bulletin.

Adobe said it had tried to replicate the flaw in Reader and Acrobat version 9.x. (and later), and found that the flaws do not affect either.

As for the remaining flaws fixed, four related to memory corruption flaws and two were general security vulnerabilities. No other details on the holes were given.

Wednesday's out-of-band update comes on the heels of Tuesday's Shockwave Player update that fixed nine critical holes that could lead to a system being remotely loaded with malware.

"These vulnerabilities could allow an attacker, who successfully exploits these vulnerabilities, to run malicious code on the affected system. Adobe recommends users of Adobe Shockwave Player and earlier versions update to Adobe Shockwave Player," sad the company.

While Adobe addressed the zero-day with a fix quickly, releasing it a day after its Shockwave rollout is rubbing some in IT the wrong way, including Andrew Storms, director of security operations for nCircle.

"I'll bet IT security teams everywhere are cursing under their breath while they rethink their patch strategies," said Storms, in an e-mail response to Adobe's patch. "It sure would have been nice if Adobe bundled all their patches together. In a perfect world, it would have been nice to get a little advance communication about the zero-day in Flash. And since we’re already wasting time fantasizing about how Adobe could make IT teams lives easier instead of harder, we should ask for a little mitigation information."

Google's Chrome Web browser, which directly integrates Flash into its software (unlike competing browsers) also received an update yesterday to reflect Adobe's patch update.   

Adobe's Flash security update can be downloaded here.

About the Author

Chris Paoli is the site producer for and


  • Microsoft Previews Azure Bastion Service for Private VM Access

    Microsoft on Tuesday announced a preview of the Azure Bastion service, which lets a user connect to an Azure virtual machine (VM) using a private Internet connection.

  • Microsoft Deprecating Windows To Go

    Microsoft plans to put an end to its Windows To Go product in the near future, according to a Friday support article.

  • Microsoft Releases Hyper-V Server 2019 After Long Delay

    Acknowledging that the release took "way too long," Microsoft has made Hyper-V Server 2019 available for download from the Microsoft Evaluation Center page.

  • Forklift Container

    A Better Way To Upgrade Hyper-V Storage

    It's time again for Brien to perform a major storage upgrade on his Hyper-V hosts. But this time, he's taking a new approach.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.