Published on: 15 November 2017
Security updates are released for Adobe Flash Player and Adobe Reader/Acrobat to address multiple vulnerabilities. To exploit the vulnerabilities, a remote attacker would entice a targeted user to open a specially crafted PDF file, web page, Flash file, or document that supports embedded Flash content.
A successful exploitation could lead to arbitrary code execution, information disclosure, excessive resource consumption, drive-by-download or attackers' control of the affected system.
Upgrade Adobe Flash Player and Adobe Reader/Acrobat to the following versions to address the issues. The upgrade can be obtained by using the auto-update mechanism or by downloading at the following URLs:
If you have multiple browsers, you are required to perform the Adobe Flash Player upgrade for each browser. The Flash Player version can be checked using the following URL:
http://www.adobe.com/software/flash/about/
https://helpx.adobe.com/security/products/acrobat/apsb17-36.html
https://helpx.adobe.com/security/products/flash-player/apsb17-33.html
https://www.hkcert.org/my_url/en/alert/17111502
https://www.us-cert.gov/ncas/current-activity/2017/11/14/Adobe-Releases-Security-Updates
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3112
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3114
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11213
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11215
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11225
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11293
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16360 (to CVE-2017-16420)