Published on: 13 May 2016
Security updates are released for Adobe Flash Player to address multiple vulnerabilities caused by type confusion, use-after-free problem, heap buffer overflow, memory corruption and directory search path errors. A remote attacker could entice a targeted user to open a specially crafted web page, Flash file, or document that supports embedded Flash content to exploit the vulnerabilities.
It is reported that the vulnerability CVE-2016-4117 is being actively exploited.
A successful attack could lead to arbitrary code execution.
Upgrade Adobe Flash Player to the following versions to address the issues. The upgrade can be obtained by using the auto-update mechanism or by downloading at the following URLs:
If you have multiple browsers, you are required to perform the Adobe Flash Player upgrade for each browser, the Flash Player version can be checked at http://www.adobe.com/software/flash/about/
https://helpx.adobe.com/security/products/flash-player/apsb16-15.html
https://www.us-cert.gov/ncas/current-activity/2016/05/12/Adobe-Releases-Security-Updates-Flash-Player
https://www.hkcert.org/my_url/en/alert/16051115
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1096 (to CVE-2016-1110)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4108 (to CVE-2016-4117)