Site icon Liquidmatrix Security Digest

New Adobe Flash Vulnerability – CVE-2015-0313

Oh, joy.

Adobe has put out yet another security bulletin for vulnerabilities in Flash.  Details:

Security Advisory for Adobe Flash Player

Release date: February 2, 2015

Vulnerability identifier: APSA15-02

CVE number: CVE-2015-0313

Platform: All Platforms

Summary

A critical vulnerability (CVE-2015-0313) exists in Adobe Flash Player 16.0.0.296 and earlier versions for Windows and Macintosh.  Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.

We are aware of reports that this vulnerability is being actively exploited in the wild via drive-by-download attacks against systems running Internet Explorer and Firefox on Windows 8.1 and below.

Adobe expects to release an update for Flash Player during the week of February 2.  For more information on updating Flash Player please refer to this post.

Affected software versions

  • Adobe Flash Player 16.0.0.296 and earlier versions for Windows and Macintosh
  • Adobe Flash Player 13.0.0.264 and earlier 13.x versions

To verify the version of Adobe Flash Player installed on your system, access the About Flash Player page, or right-click on content running in Flash Player and select “About Adobe (or Macromedia) Flash Player” from the menu. If you use multiple browsers, perform the check for each browser you have installed on your system.

Severity ratings

Adobe categorizes this as a critical vulnerability.

Acknowledgments

Adobe would like to thank the following individuals and organizations for reporting CVE-2015-0313 and for working with Adobe to help protect our customers:

  • Elia Florio and Dave Weston of Microsoft
  • Peter Pi of Trend Micro

Revisions

February 2, 2015 – removed Flash Player version 11.x from the list of affected versions.  Version 11.x and earlier do not support the functionality affected by CVE-2015-0313.

Exit mobile version