Published on: 17 June 2016
Security updates are released for Adobe Flash Player to address multiple vulnerabilities caused by type confusion, use-after-free problem, buffer overflow, memory corruption and directory search path errors. A remote attacker could entice a targeted user to open a specially crafted web page, Flash file, or document that supports embedded Flash content to exploit the vulnerabilities.
It is reported that the vulnerability CVE-2016-4171 is being actively exploited in targeted attacks.
A successful attack could lead to arbitrary code execution, security restriction bypass or information disclosure.
Upgrade Adobe Flash Player to the following versions to address the issues. The upgrade can be obtained by using the auto-update mechanism or by downloading at the following URLs:
If you have multiple browsers, you are required to perform the Adobe Flash Player upgrade for each browser, the Flash Player version can be checked at http://www.adobe.com/software/flash/about/
https://helpx.adobe.com/security/products/flash-player/apsb16-18.html
https://helpx.adobe.com/security/products/air/apsb16-23.html
https://www.us-cert.gov/ncas/current-activity/2016/06/16/Adobe-Releases-Security-Updates
https://www.hkcert.org/my_url/en/alert/16061517
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4122 (to CVE-2016-4156)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4166
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4171