[SingCERT] Security update available for Adobe Flash Player
- Published on Friday, 23 September 2011 10:41
[ Summary ]
Critical vulnerabilities have been identified in Adobe Flash Player 10.3.183.7 and earlier versions for Windows, Macintosh, Linux and Solaris, and Adobe Flash Player 10.3.186.6 and earlier versions for Android. These vulnerabilities could cause a crash and potentially allow an attacker to take control of the affected system
[ Affected Systems ]
- Adobe Flash Player 10.3.183.7 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems
- Adobe Flash Player 10.3.186.6 and earlier versions for Android
[ Impact Analysis ]
There are reports that one of these vulnerabilities (CVE-2011-2444) is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message. This universal cross-site scripting issue could be used to take actions on a user’s behalf on any website or webmail provider if the user visits a malicious website.
[ Solution/Workaround ]
Please update Adobe Flash Player to the latest version. See reference for links to download.
[ Reference ]