Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Adobe acknowledges critical remote vulnerability in Flash, exploits already in the wild
AppleInsider ^ | Sunday, January 25, 2015 | By AppleInsider Staff

Posted on 01/25/2015 9:08:43 PM PST by Swordmaker

Adobe on Saturday released an updated version of its Flash player software that patches an undisclosed vulnerability which could allow remote attackers to take control of Macs or PCs, urging users to update as the problem is being actively exploited by malicious actors.

Flash versions up to and including 16.0.0.287 on OS X and Windows and 11.2.202.438 on Linux are susceptible to the attack, the cause of which has yet to be detailed. Mac users with Adobe's automatic update feature enabled should begin receiving updates to version 16.0.0.296 immediately, and the company is preparing a standalone patch for manual installation to be released this week. Adobe is also working with Google to update the embedded version of Flash included in the Chrome browser.

The vulnerability — which has been assigned CVE number 2015-0311 — is "being actively exploited in the wild via drive-by-download attacks against systems running Internet Explorer and Firefox on Windows 8.1 and below," Adobe said in a security advisory. A "drive-by-download" attack is one in which software is downloaded to a user's computer without their knowledge or explicit consent.

Adobe defines CVE-2015-0311 as "critical," meaning a "vulnerability, which, if exploited would allow malicious native-code to execute, potentially without a user being aware."

Users can check the version of Flash installed on their system by visiting Adobe's About Flash Player page or right-clicking on Flash content in their browser and choosing "About Adobe (or Macromedia) Flash Player" from the contextual menu. Instructions for enabling automatic updates or manually updating Flash can be found here.


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: adobe; adobeflash; adobeflashplayer; computers; computing; flash
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-68 next last

1 posted on 01/25/2015 9:08:43 PM PST by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: Swordmaker

Oh great. Another eleven or twelve “updates” of Adobe flash I have to install, with an attendant eleven or twelve times Adobe tries to slip Chrome past me.


2 posted on 01/25/2015 9:11:16 PM PST by Steely Tom (Vote GOP for A Slower Handbasket)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; altair; ...
Adobe announces an update to Adobe FLASH. . . fixes a vulnerability which can allow a REMOTE hacker to take over both Windows 8.1 and Apple Mac OS X computer. . . for which there are ACTIVE Exploits in the wild for Windows computers! So far, no one has seen any exploits for OS X, but that does not mean they are not possible!

Users of both platforms should UPDATE or DELETE ADOBE FLASH IMMEDIATELY! — PING!


Apple OS X AND Microsoft Windows 8.1 SECURITY Ping!

If you want on or off the Mac Ping List, Freepmail me.

3 posted on 01/25/2015 9:12:58 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CodeToad

Important. Ping Windows users to this thread, Coad.


4 posted on 01/25/2015 9:16:57 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Swordmaker

I removed flash a few major exploit announcements ago. I haven’t missed it.


5 posted on 01/25/2015 9:24:38 PM PST by enduserindy (A painted trash can is still a trash can.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Jonty30; Bellagio; relictele; moose07; Fresh Wind; Mad Dawgg

Got an assignment for you guys.... this is important. FLASH has a big hole in it and we need to get Windows users to either update it or delete it! Can you guys ping windows users to this thread?


6 posted on 01/25/2015 9:29:05 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: SunTzuWu; SZonian; vpintheak; smokingfrog; TigersEye; Regulator; KoRn; BBB333; thackney; ...

Hey, Guys. . . I need to ask you a favor. . . It seems that Adobe announced early Sunday morning that Adobe FLASH has a huge vulnerability that allows a remote hacker to take complete control over both Windows 8.1 or Apple OS X . . . and there are already EXPLOITS out there in the wild for Windows, but not for OS X, yet. But we need to get the word out to WINDWS and MAC users to either DELETE FLASH or UPDATE it immediately. . . Can you please ping any Windows users you know to this thread so they can get the straight info? Thanks!


7 posted on 01/25/2015 9:44:06 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Swordmaker

Adobe isn’t rushing out to get people to update so I’d suggest holding off on the world-is-ending hype. This is all pretty stupid. As another writer says, this only leads to multiple updates, slipped in 3rd party installs, etc.

Further, the info and links are suspect or dated. As I use Adobe Connect for my business, I checked my Flash install—I already have a newer version than any referenced. Best course of action is to simply set for automatic updates and relax. Might not address everything, but sure beats the world-is-ending hype.


8 posted on 01/25/2015 9:46:06 PM PST by Reno89519 (For every illegal or H1B with a job, there's an American without one. Muslim = Nazi = Evil)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Reno89519
Adobe isn’t rushing out to get people to update so I’d suggest holding off on the world-is-ending hype. This is all pretty stupid. As another writer says, this only leads to multiple updates, slipped in 3rd party installs, etc.

Adobe always runs under the radar with the updates. . . and leaves people hanging in the wind. There are exploits in the wild. Many people have turned off their auto-updates. I think it is better that users be aware there is a problem with their FLASH player then ignorantly continue as they are. That's why I put "DELETE" in the announcement. They can do as they choose. It's posted. Freepers can do as they choose. . . as can you. In my opinion, it is not HYPE.

9 posted on 01/25/2015 10:04:01 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Swordmaker
Anyone who wants to find out what version of Adobe is on the computer they are using can go here:
http://helpx.adobe.com/flash-player/kb/installation-problems-flash-player-windows.html
10 posted on 01/25/2015 10:24:00 PM PST by jonatron
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

How would I go about deleting it? I’m not that computer tech savvy.


11 posted on 01/25/2015 10:32:16 PM PST by CaptainK (...please make it stop. Shake a can of pennies at it.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: CaptainK
How would I go about deleting it? I’m not that computer tech savvy.

Adobe doesn't play by the rules Apple has established. To properly get rid of Adobe Flash Player you need to download the appropriate uninstaller for your version on OS X and run it.

12 posted on 01/25/2015 10:40:13 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Swordmaker

I’m looking at a site called Softpedia where it says I can download an Adobe Flash Player Uninstaller 16.0.0.287.

Is that what you mean?


13 posted on 01/25/2015 10:51:53 PM PST by CaptainK (...please make it stop. Shake a can of pennies at it.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Reno89519

Assuming this isn’t just a rumor, the upgrade isn’t available yet from Adobe.


14 posted on 01/25/2015 10:58:52 PM PST by Kirkwood (Zombie Hunter)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Swordmaker
At this writing Adobe is still pushing Flash 16.0.0.287 for Windows 7 and 16.0.0.257 for Vista from the "Get Adobe Flash" link, http://get.adobe.com/flashplayer/. Mozilla plugin check (https://www.mozilla.org/en-US/plugincheck/) reports both versions as up to date.
15 posted on 01/25/2015 11:45:42 PM PST by TChad (The Obamacare motto: Dulce et decorum est pro patria mori.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: TChad
Apparently Flash for Windows started automatically installing the patch on January 24 if auto-updates are enabled.

A manual download with the patch will be available this week, meaning that those of us who don't use auto-update will be at risk.

Thanks heaps, Adobe. You've done it again!

16 posted on 01/26/2015 12:01:21 AM PST by TChad (The Obamacare motto: Dulce et decorum est pro patria mori.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: CaptainK

No, go directly to Adobe.com for any Adobe downloads. NEVER under any circumstances ever download an Adobe download from any other source. . . especially one from an email or a pop-up. That’s the way malware can get on your computer.


17 posted on 01/26/2015 12:04:34 AM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 13 | View Replies]

To: TChad
Thanks heaps, Adobe. You've done it again!

DAMN. My point exactly. Adobe is famous for leaving people waving gently in the wind. . .

18 posted on 01/26/2015 12:06:03 AM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 16 | View Replies]

To: Swordmaker

Excellent advice.

Even if you go to the A-dope-y website, by installing the update you always get an extra bonus payload, some sort of useless security scan software from McAfee, and there’s no way I’ve found to opt out of it. I have to delete it every time. Grrr.

I don’t know if they do that to Apple users, but I wouldn’t put it past them.

Thank you for posting this thread.


19 posted on 01/26/2015 3:36:06 AM PST by Fresh Wind (The last remnants of the Old Republic have been swept away)
[ Post Reply | Private Reply | To 17 | View Replies]

To: Swordmaker; onyx; TheOldLady; RedMDer; deoetdoctrinae; Lady Jag; trisham; MEG33; bd476; ...
Your presence has been requested in the Drawing room....
ADOBIE has dropped another one.

20 posted on 01/26/2015 4:13:01 AM PST by moose07 (The Camels have reached the parking lot. Shields up!)
[ Post Reply | Private Reply | To 6 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-68 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson