Adobe will issue an emergency patch tomorrow for a critical vulnerability in its Flash Player that is currently actively exploited by cybercriminals. The vulnerability exists in Windows XP and Windows 7 and can be used to take full control over a victim's computer.

The vulnerability exists in Adobe Flash Player 21.0.0.197 and earlier versions for Windows, Macintosh, Linux, and Chrome OS. Visiting a hacked or malicious website or viewing a malicious advertisement is sufficient to become infected.
Although the vulnerability is in Flash Player 21.0.0.197 and earlier, it is being actively exploited on systems running Windows 7 and Windows XP with Flash Player version 20.0.0.306 and earlier. A mitigation introduced in Flash Player 21.0.0.182 currently prevents exploitation of this vulnerability, protecting users running Flash Player 21.0.0.182 and later.
Adobe therefore advices users to update to the most recent version of Flash Player. The company will also release an emergency patch tomorrow that fixes the vulnerability.
The list of Flash Player vulnerabilities, whether they are actively exploited before or after Adobe released a patch keeps growing.















