Security Adobe Flash Player
adobe security bulletins , advisories announce security updates, adobe flash player release notes not disclose security issues addressed when release closes security holes, making difficult evaluate urgency of particular update. version test page allows user check if latest version installed, , uninstallers may used ensure old-version plugins have been uninstalled installed browsers.
in february 2010, adobe officially apologized not fixing known vulnerability on year. in june 2010 adobe announced critical vulnerability in recent versions, saying there reports vulnerability being actively exploited in wild against both adobe flash player, , adobe reader , acrobat. later, in october 2010, adobe announced critical vulnerability, time affecting android-based mobile devices. android users have been recommended disable flash or make on demand. subsequent security vulnerabilities exposed android users, such 2 critical vulnerabilities published in february 2013 or 4 critical vulnerabilities published in march 2013, of lead arbitrary code execution.
symantec s internet security threat report states remote code execution in adobe reader , flash player second attacked vulnerability in 2009. same report recommended using browser extensions disable flash player usage on untrusted websites. mcafee predicted adobe software, reader , flash, primary target attacks in 2010. adobe applications had become, @ least @ point, popular client-software targets attackers during last quarter of 2009. kaspersky security network published statistics third quarter of 2012 showing 47.5% of users affected 1 or more critical vulnerabilities. report highlighted flash player vulnerabilities enable cybercriminals bypass security systems integrated application.
steve jobs criticized security of flash player, noting symantec highlighted flash having 1 of worst security records in 2009 . adobe responded pointing out symantec global internet threat report 2009, found flash player had second lowest number of vulnerabilities of internet technologies listed (which included both web plug-ins , browsers).
april 7, 2016, adobe released flash player patch zero-day memory corruption vulnerability cve-2016-1019 used deliver malware via magnitude exploit kit. vulnerability exploited remote code execution.
Comments
Post a Comment