February 15, 2012
Today, a Security Bulletin (APSB12-03) has been posted to address critical security issues in Adobe Flash Player 11.1.102.55 and earlier versions for Windows, Macintosh, Linux and Solaris, Adobe Flash Player 11.1.112.61 and earlier versions for Android 4.x, and Adobe Flash Player 11.1.111.5 and earlier versions for Android 3.x and 2.x. Adobe recommends users apply the updates for their product installations. There are reports that a cross-site scripting vulnerability (CVE-2012-0767) addressed in this update is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message (Internet Explorer on Windows only).
This posting is provided “AS IS” with no warranties and confers no rights.
November 10, 2011
Today, a Security Bulletin (APSB11-28) has been posted to address critical security issues in Adobe Flash Player. This Security Bulletin affects Flash Player 11.0.1.152 and earlier versions for Windows, Macintosh, Linux and Solaris, and Flash Player 11.0.1.153 for Android. Adobe recommends users apply the updates for their product installations.
This posting is provided “AS IS” with no warranties and confers no rights.
October 20, 2011
Adobe is aware of a report describing a clickjacking issue related to the online Flash Player Settings Manager. We have resolved the issue with a change to the Flash Player Settings Manager SWF file hosted on the Adobe website. No user action or Flash Player product update are required.
This posting is provided “AS IS” with no warranties and confers no rights.
September 21, 2011
Today, a Security Bulletin (APSB11-26) has been posted to address critical security issues in Adobe Flash Player. This Security Bulletin affects Flash Player 10.3.183.7 and earlier versions for Windows, Macintosh, Linux and Solaris, and Flash Player 10.3.186.6 for Android. There are reports that one of these vulnerabilities (CVE-2011-2444) is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message. This universal cross-site scripting issue could be used to take actions on a user’s behalf on any website or webmail provider if the user visits a malicious website. Adobe recommends users apply the updates for their product installations.
This posting is provided “AS IS” with no warranties and confers no rights.
September 20, 2011
A Flash Player update is scheduled for release tomorrow, September 21, 2011. This update will address critical security issues in the product as well as an important universal cross-site scripting issue that is reportedly being exploited in the wild in targeted attacks.
We will continue to provide updates on the upcoming release via the Security Advisory section of the Adobe website as well as the Adobe PSIRT blog.
This posting is provided “AS IS” with no warranties and confers no rights.
August 9, 2011
Today, we released the following Security Bulletins:
Customers of the affected products should consult the relevant Security Bulletin(s) and apply updates as recommended.
This posting is provided “AS IS” with no warranties and confers no rights.
June 14, 2011
Today, we released the following Security Bulletins:
Customers of the affected products should consult the relevant Security Bulletin(s) and apply updates as recommended.
This posting is provided “AS IS” with no warranties and confers no rights.
June 5, 2011
Today, a Security Bulletin (APSB11-13) has been posted to address an important security issue (CVE-2011-2107) in Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris, and Adobe Flash Player 10.3.185.22 and earlier versions for Android. Adobe recommends users apply the updates for their product installations.
This posting is provided “AS IS” with no warranties and confers no rights.
May 12, 2011
Today, we released the following Security Bulletins:
Customers of the affected products should consult the relevant Security Bulletin(s) and apply updates as recommended.
On a related note, we recently added an Acknowledgments page on the Adobe website to thank the individuals and organizations who report a security vulnerability or vulnerabilities in an Adobe product or online service. For acknowledgments of individuals and organizations reporting a security vulnerability or vulnerabilities in an Adobe product, please refer to the “Acknowledgments” section in each Security Bulletin. The new page will list the individuals and organizations who report a security vulnerability or vulnerabilities in an Adobe online service, and worked with us to help protect our customers.
This posting is provided “AS IS” with no warranties and confers no rights.
April 15, 2011
Today, a Security Bulletin (APSB11-07) has been posted to address a critical security issue (CVE-2011-0611) in Adobe Flash Player 10.2.153.1 and earlier versions (Adobe Flash Player 10.2.154.25 and earlier for Chrome users) for Windows, Macintosh, Linux and Solaris, as referenced in Security Advisory APSA11-02. Adobe recommends users apply the updates for their product installations.
This posting is provided “AS IS” with no warranties and confers no rights.