Description:
Security updates are released for Adobe Flash Player and Adobe Reader/Acrobat to address multiple vulnerabilities. To exploit the vulnerabilities, a remote attacker would entice a targeted user to open a specially crafted PDF file, web page, Flash file, or document with embedded malicious Flash content.
Please note that Adobe announced that the support for Adobe Flash will be ceased at the end of 2020 and no security updates will be provided after that. The support for Adobe Acrobat XI 11.x and Adobe Reader XI 11.x ended on 15.10.2017. Users should arrange migrating to other supported technology.
Affected Systems:
- Adobe Flash Player Desktop Runtime for Windows, Macintosh and Linux 30.0.0.134 and earlier versions
- Adobe Flash Player for Google Chrome 30.0.0.134 and earlier versions
- Adobe Flash Player for Microsoft Edge and Internet Explorer 11 30.0.0.134 and earlier versions
- Adobe Acrobat/Acrobat Reader 2017 2017.011.30096 and earlier versions
- Adobe Acrobat DC/Acrobat Reader DC Continuous 2018.011.20055 and earlier versions
- Adobe Acrobat DC/Acrobat Reader DC Classic 2015.006.30434 and earlier versions
Impact:
A successful exploitation could lead to arbitrary code execution and take control of an affected system.
Recommendation:
Upgrade Adobe Flash Player and Adobe Reader/Acrobat to the following versions to address the issues. The upgrade can be obtained by using the auto-update mechanism or by downloading at the following URLs:
- Adobe Flash Player Desktop Runtime 30.0.0.154 for Windows and Macintosh
https://get.adobe.com/flashplayer/
http://www.adobe.com/products/players/flash-player-distribution.html
- Adobe Flash Player 30.0.0.154 for Google Chrome
https://chromereleases.googleblog.com/
- Adobe Flash Player 30.0.0.154 for Microsoft Edge and Internet Explorer 11
https://portal.msrc.microsoft.com/en-US/security-guidance/
- Adobe Flash Player 30.0.0.154 for Linux
https://get.adobe.com/flashplayer/
- Acrobat DC (Continuous) 2018.011.20058
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Mac
- Acrobat Reader DC (Continuous) 2018.011.20058
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Mac
- Acrobat 2017 2017.011.30099
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Mac
- Acrobat Reader DC 2017 2017.011.30099
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Mac
- Acrobat Reader DC (Classic 2015) 2015.006.30448
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Mac
- Acrobat DC (Classic 2015) 2015.006.30448
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Mac
If you have multiple browsers, you are required to perform the Adobe Flash Player upgrade for each browser, the Flash Player version can be checked at
http://www.adobe.com/software/flash/about/
More Information:
- https://helpx.adobe.com/security/products/flash-player/apsb18-25.html
- https://helpx.adobe.com/security/products/acrobat/apsb18-29.html
- https://helpx.adobe.com/acrobat/kb/end-of-support-acrobat-xi-reader-xi.html
- https://www.us-cert.gov/ncas/current-activity/2018/08/14/Adobe-Releases-Security-Updates
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12799
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12808
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12824 (to CVE-2018-12828)