Published on: 09 December 2015
Security updates are released for Adobe Flash Player to address multiple vulnerabilities caused by memory corruption, various buffer overflow, type confusion, use-after-free error and security bypass problems. A remote attacker could entice a targeted user to open a specially crafted web page, Flash file, or document that supports embedded Flash content to exploit the vulnerabilities.
A successful attack could lead to bypass of security restrictions, arbitrary code execution or potentially take control of the affected system.
Upgrade Adobe Flash Player to the following versions to address the issues. The upgrade can be obtained by using the auto-update mechanism or by downloading at the following URLs:
If you have multiple browsers, you are required to perform the Adobe Flash Player upgrade for each browser, the Flash Player version can be checked at http://www.adobe.com/software/flash/about/
https://helpx.adobe.com/security/products/flash-player/apsb15-32.html
https://technet.microsoft.com/library/security/2755801
https://www.hkcert.org/my_url/en/alert/15120913
https://www.us-cert.gov/ncas/current-activity/2015/12/08/Adobe-Releases-Security-Updates-Flash-Player
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8045
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8047 (to CVE-2015-8050)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8055 (to CVE-2015-8071)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8401 (to CVE-2015-8455)