Adobe Flash Flaw Gets Zero-Day Fix

Adobe on Wednesday released a security update that fixed seven Flash Player vulnerabilities, including a zero-day cross-site scripting (XSS) flaw found by Google researchers.

The vulnerability, classified as "critical" by Adobe, could allow an attacker to gain access to a user's computer after visiting a malicious e-mail or Web site. Adobe has reported that systems have already been compromised using this flaw.

"There are reports that this vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an e-mail message," said Adobe in a security bulletin.

Adobe said it had tried to replicate the flaw in Reader and Acrobat version 9.x. (and later), and found that the flaws do not affect either.

As for the remaining flaws fixed, four related to memory corruption flaws and two were general security vulnerabilities. No other details on the holes were given.

Wednesday's out-of-band update comes on the heels of Tuesday's Shockwave Player update that fixed nine critical holes that could lead to a system being remotely loaded with malware.

"These vulnerabilities could allow an attacker, who successfully exploits these vulnerabilities, to run malicious code on the affected system. Adobe recommends users of Adobe Shockwave Player and earlier versions update to Adobe Shockwave Player," sad the company.

While Adobe addressed the zero-day with a fix quickly, releasing it a day after its Shockwave rollout is rubbing some in IT the wrong way, including Andrew Storms, director of security operations for nCircle.

"I'll bet IT security teams everywhere are cursing under their breath while they rethink their patch strategies," said Storms, in an e-mail response to Adobe's patch. "It sure would have been nice if Adobe bundled all their patches together. In a perfect world, it would have been nice to get a little advance communication about the zero-day in Flash. And since we’re already wasting time fantasizing about how Adobe could make IT teams lives easier instead of harder, we should ask for a little mitigation information."

Google's Chrome Web browser, which directly integrates Flash into its software (unlike competing browsers) also received an update yesterday to reflect Adobe's patch update.   

Adobe's Flash security update can be downloaded here.

About the Author

Chris Paoli is the site producer for and


  • Surface and ARM: Why Microsoft Shouldn't Follow Apple's Lead and Dump Intel

    Microsoft's current Surface flagship, the Surface Pro X, already runs on ARM. But as the ill-fated Surface RT showed, going all-in on ARM never did Microsoft many favors.

  • IT Security Isn't Supposed To Be Easy

    Joey explains why it's worth it to endure a little inconvenience for the long-term benefits of a password manager and multifactor authentication.

  • Microsoft Makes It Easier To Self-Provision PCs via Windows Autopilot When VPNs Are Used

    Microsoft announced this week that the Windows Autopilot service used with Microsoft Intune now supports enrolling devices, even in cases where virtual private networks (VPNs) might get in the way.

  • Most Microsoft Retail Locations To Shut Down

    Microsoft is pivoting its retail operations to focus more on online sales, a plan that would mean the closing of most physical Microsoft Store locations.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.