Adobe Flash Flaw Gets Zero-Day Fix

Adobe on Wednesday released a security update that fixed seven Flash Player vulnerabilities, including a zero-day cross-site scripting (XSS) flaw found by Google researchers.

The vulnerability, classified as "critical" by Adobe, could allow an attacker to gain access to a user's computer after visiting a malicious e-mail or Web site. Adobe has reported that systems have already been compromised using this flaw.

"There are reports that this vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an e-mail message," said Adobe in a security bulletin.

Adobe said it had tried to replicate the flaw in Reader and Acrobat version 9.x. (and later), and found that the flaws do not affect either.

As for the remaining flaws fixed, four related to memory corruption flaws and two were general security vulnerabilities. No other details on the holes were given.

Wednesday's out-of-band update comes on the heels of Tuesday's Shockwave Player update that fixed nine critical holes that could lead to a system being remotely loaded with malware.

"These vulnerabilities could allow an attacker, who successfully exploits these vulnerabilities, to run malicious code on the affected system. Adobe recommends users of Adobe Shockwave Player and earlier versions update to Adobe Shockwave Player," sad the company.

While Adobe addressed the zero-day with a fix quickly, releasing it a day after its Shockwave rollout is rubbing some in IT the wrong way, including Andrew Storms, director of security operations for nCircle.

"I'll bet IT security teams everywhere are cursing under their breath while they rethink their patch strategies," said Storms, in an e-mail response to Adobe's patch. "It sure would have been nice if Adobe bundled all their patches together. In a perfect world, it would have been nice to get a little advance communication about the zero-day in Flash. And since we’re already wasting time fantasizing about how Adobe could make IT teams lives easier instead of harder, we should ask for a little mitigation information."

Google's Chrome Web browser, which directly integrates Flash into its software (unlike competing browsers) also received an update yesterday to reflect Adobe's patch update.   

Adobe's Flash security update can be downloaded here.

About the Author

Chris Paoli is the site producer for and


  • Microsoft Previews Windows Autopilot for HoloLens 2

    Microsoft on Friday announced a public preview of Windows Autopilot for HoloLens 2, its mixed-reality headset.

  • Microsoft Flirts with Charging for API Software Connections

    Microsoft may have started something new by attempting to charge its customers for software that uses its application programming interfaces (APIs).

  • Overcoming Spacesuit Anxiety During Astronaut Training

    Spacesuits are heavy, claustrophobic and hot -- an uncomfortable combination for many would-be astronauts. Here's how Brien came around to the idea of wearing one.

  • Microsoft Announces Azure Kubernetes Service Enhancements

    Microsoft this week announced a few Azure Kubernetes Service (AKS) product milestones as part of the KubeCon event.

comments powered by Disqus