Adobe Releases Critical Flash Player Update Not Related to Weekend Zero-day Announcement

Adobe Releases Critical Flash Player Update Not Related to Weekend Zero-day Announcement

In light of a reported, zero-day vulnerability in the Flash player component for all versions of Internet Explorer over the weekend, it's not surprising to see that a critical Flash Player update has been released by Adobe today. However, the update is not what you think. It does not address the zero-day weekender, but seeks to plug a different hole in Adobe software.

The new update will be installed automatically for those using IE10, IE11, and Google Chrome, but those using earlier versions of Internet Explorer should grab this update to patch immediately. Also, Adobe's reported flaw also affects Windows, Mac, and Linux systems running versions of Flash Player as follows…

  • Users of Adobe Flash Player 13.0.0.182 and earlier versions for Windows should update to Adobe Flash Player 13.0.0.206.
  • Users of Adobe Flash Player 13.0.0.201 and earlier versions for Macintosh should update to Adobe Flash Player 13.0.0.206.
  • Users of Adobe Flash Player 11.2.202.350 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.356.

Keep in mind, this does NOT address the IE flaw reported over the weekend. This Adobe security problem stands on its own.

More information can be found in Adobe Security Bulletin APSB14-13:  Security updates available for Adobe Flash Player

Microsoft has mirrored the release of Adobe's security bulletin with a security announcement of it's own: Microsoft Security Advisory 2755801

Get patched!

Hide comments

Comments

  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
Publish