Adobe fixes 25 vulnerabilities in Flash Player - including 1 zero-day leak

Adobe today released an update for Flash Player that patches 25 vulnerabilities, including a zero-day leak that allows an attacker to take full control over the computer. All 25 vulnerabilities could be used to execute random code on computers.

myce-adobeflash

To become victim of an exploit no more than visiting a hacked or malicious website or viewing a malicious advertisement is required. No further user interaction is required in order to become victim of an attack exploiting any of the vulnerabilities.

It's unclear whether the zero-day leak, which means a disclosed vulnerability for which no patch was available yet, is actively attacked.

Adobe advises users to update to Flash Player 21.0.0.242 as soon as possible either through the automatic update feature of Flash or through Adobe.com.

The embedded Flash player of Google Chrome, Internet Explorer 10 and 11 on Windows 8 and 8.1 and Internet Explorer 11 and Edge on Windows 10 will be automatically updated, both Google and Microsoft already released updates.

No posts to display