Description:
Security updates are released for Adobe Flash Player and Adobe Reader/Acrobat to address multiple vulnerabilities caused by heap buffer overflow, integer buffer overflow, use-after-free error, memory corruption, and directory search path issue. To successfully exploit the vulnerabilities, a remote attacker could entice a targeted user to open a specially crafted PDF file, web page, Flash file, or document that supports embedded Flash content.
Affected Systems:
- Adobe Flash Player Desktop Runtime for Windows, Macintosh and Linux 25.0.0.127 and earlier versions
- Adobe Flash Player for Google Chrome 25.0.0.127 and earlier versions
- Adobe Flash Player for Microsoft Edge and Internet Explorer 11 25.0.0.127 and earlier versions
- Adobe Acrobat DC/Acrobat Reader DC Continuous 15.023.20070 and earlier versions
- Adobe Acrobat DC/Acrobat Reader DC Classic 15.006.30280 and earlier versions
- Adobe Acrobat/Reader XI 11.0.19 and earlier versions
Impact:
A successful exploitation could lead to arbitrary code execution, memory address leakage or potentially take control of the affected system.
Recommendation:
Upgrade Adobe Flash Player and Adobe Reader/Acrobat to the following versions to address the issues. The upgrade can be obtained by using the auto-update mechanism or by downloading at the following URLs:
- Adobe Flash Player Desktop Runtime 25.0.0.148 for Windows and Macintosh
http://www.adobe.com/go/getflash
http://www.adobe.com/products/players/flash-player-distribution.html
- Adobe Flash Player 25.0.0.148 for Google Chrome
http://googlechromereleases.blogspot.com/
- Adobe Flash Player 25.0.0.148 for Microsoft Edge and Internet Explorer 11
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/2017-3447
- Adobe Flash Player 25.0.0.148 for Linux
http://www.adobe.com/go/getflash
- Adobe Acrobat DC Continuous 2017.009.20044, Classic 2015.006.30306, Acrobat XI 11.0.20
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Mac
- Adobe Acrobat Reader DC Classic 2015.006.30306, Reader XI 11.0.20
http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Mac
- Adobe Acrobat Reader DC Continuous 2017.009.20044
http://get.adobe.com/reader/
If you have multiple browsers, you are required to perform the Adobe Flash Player upgrade for each browser, the Flash Player version can be checked at
http://www.adobe.com/software/flash/about/
More Information:
https://helpx.adobe.com/security/products/acrobat/apsb17-11.html
https://helpx.adobe.com/security/products/flash-player/apsb17-10.html
https://www.hkcert.org/my_url/en/alert/17041202
https://www.us-cert.gov/ncas/current-activity/2017/04/11/Adobe-Releases-Security-Updates
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3011 (to CVE2017-3015)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3017 (to CVE2017-3065)