Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Adobe Flash Player Update Released for Remote Code Execution Vulnerability
#1
Quote:Adobe released a security update yesterday that resolves a critical vulnerability in Flash Player that could allow malicious sites to execute code on your computer.

According to the Adobe APSB18-44 bulletin, this vulnerability has a CVE ID of CVE-2018-15981 and is a Type Confusion vulnerability that could allow remote code execution. This means that an attacker can create a malicious SWF file, host it on a web site, and exploit vulnerable visitors when they browse the site. This would then allow them to execute any command on the computer such as downloading and installing malware.

A security update for Adobe Flash Player was already released this month on November 13th along with updates for other products. The reason Adobe has released another update is because the technical information regarding this vulnerability has already been posted online and could be used by attackers to create a working exploit.

It seems that on the same day that the November 13th Flash Player update was released, a blog post was published that provided a detailed overview of a type confusion vulnerability in Flash Player.

TLDR; There’s a bug in Adobe Flash," stated the blog post. "The interpreter code of the Action Script Virtual Machine (AVM) does not reset a with-scope pointer when an exception is caught, leading later to a type confusion bug, and eventually to a remote code execution."

According to Eduard Kovacs of Security Week, this blog belongs to an Israel-based researcher name Gil Dabah. It is not known why the vulnerability was disclosed publicly.

Ultimate, if for you are still using Flash for some reason, you need to update immediately in order to protect yourself while browsing the web. To resolve this vulnerability, users can upgrade to Adobe Flash Player 31.0.0.153.

SOURCE
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Vulnerabilities in WatchGuard, Panda Security Products Lead to Code Execution mrtrout 0 475 02-04-2024 , 06:49 AM
Last Post: mrtrout
  PyPI removes 'mitmproxy2' over code execution concerns mrtrout 0 549 10-12-2021 , 10:43 PM
Last Post: mrtrout
  "git clone" Hit By Vulnerability That Could Lead To Code Execution Bjyda 0 1,107 03-11-2021 , 10:30 PM
Last Post: Bjyda
  Adobe Patches Code Execution Flaws in Connect, Creative Cloud, Framemaker Bjyda 0 979 03-10-2021 , 12:14 AM
Last Post: Bjyda
  VMware addresses Remote Code Execution issue in View Planner Bjyda 0 1,001 03-05-2021 , 12:16 AM
Last Post: Bjyda

Forum Jump:


Users browsing this thread: 1 Guest(s)