Adobe has released Version 28.0.0.161 of Adobe Flash Player. These updates address critical vulnerabilities that could lead to remote code execution in Adobe Flash Player 28.0.0.137 and earlier versions. Successful exploitation could potentially allow an attacker to take control of the affected system.
In particular, the update addresses CVE-2018-4878 which exists in the wild, and is being used in limited, targeted attacks against Windows users. These attacks leverage Office documents with embedded malicious Flash content distributed via email. Also included in the update are functional fixes.
Release date: February 6, 2018
Vulnerability identifier: APSB18--03
Platform: Windows, Macintosh, Linux and Chrome OS
Update:
- With the option to 'Allow Adobe to install updates', the update will be automatic. Without that setting enabled, either install the update via the update mechanism when prompted or via the Download Center*.
- Windows 7 and earlier: Installation links for Windows 7 and earlier are provided by Adobe at Installation problems | Flash Player | Windows 7 and earlier (https://helpx.adobe.com/flash-player/kb/installation-problems-flash-player-windows.html):
- Flash Player for Internet Explorer - ActiveX (https://fpdownload.macromedia.com/pub/flashplayer/latest/help/install_flash_player_ax.exe)
- Flash Player for Firefox/Pale Moon - NPAPI (https://fpdownload.macromedia.com/pub/flashplayer/latest/help/install_flash_player.exe)
- Flash Player for Opera and Chromium-based browsers - PPAPI (https://fpdownload.macromedia.com/pub/flashplayer/latest/help/install_flash_player_ppapi.exe)
- Microsoft Edge and Internet Explorer 11: Adobe Flash Player will be automatically updated to the latest version for Windows 8.1 and 10.
- Google Chrome: Adobe Flash Player will be automatically updated to the latest Google Chrome version.
- Flash Player Uninstaller: http://download.macromedia.com/get/flashplayer/current/support/uninstall_flash_player.exe (http://download.macromedia.com/get/flashplayer/current/support/uninstall_flash_player.exe)
- Adobe AIR: Adobe - Adobe AIR (http://get.adobe.com/air/)
*Important Note: Downloading the update from the Adobe Flash Player Download Center (http://get.adobe.com/flashplayer/) link includes a pre-checked option to install unnecessary extras, such as McAfee Scan Plus or Google Drive. If you use the download center, uncheck any unnecessary extras that you do not want. They are not needed for the Flash Player update.
Security Bulletin (https://helpx.adobe.com/security/products/flash-player/apsb18-03.html)
Flash Player® 28 AIR® 28 (https://helpx.adobe.com/flash-player/release-note/fp_28_air_28_release_notes.html)
Microsoft has released the Flash Player update: February 2018 Security Updates (https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/879af9c3-970b-e811-a961-000d3a33c573)
Quote
Release Date: February 06, 2018
The out-of-band February 6 security release consists of security updates for Adobe Flash.