Security Advisory for Adobe Flash Player (APSA15-03)

A Security Advisory (APSA15-03) has been published regarding a critical vulnerability (CVE-2015-5119) in Adobe Flash Player 18.0.0.194 and earlier versions for Windows, Macintosh and Linux.

Adobe is aware of reports that an exploit targeting this vulnerability has been publicly published. Adobe expects to make updates available on July 8, 2015.

This posting is provided “AS IS” with no warranties and confers no rights.

Security updates available for Adobe Flash Player (APSB15-14)

A Security Bulletin (APSB15-14) has been published regarding security updates for Adobe Flash Player. These updates address a critical vulnerability (CVE-2015-3113), and Adobe recommends users update their product installations to the latest versions using the instructions referenced in the security bulletin.

Adobe is aware of reports that CVE-2015-3113 is being actively exploited in the wild via limited, targeted attacks. Systems running Internet Explorer for Windows 7 and below, as well as Firefox on Windows XP, are known targets.

This posting is provided “AS IS” with no warranties and confers no rights.

Security updates available for Adobe Flash Player (APSB15-11)

A Security Bulletin (APSB15-11) has been published regarding security updates for Adobe Flash Player. These updates address critical vulnerabilities, and Adobe recommends users update their product installations to the latest versions using the instructions referenced in the security bulletin.

This posting is provided “AS IS” with no warranties and confers no rights.

Adobe Security Bulletins Posted

The following Security Bulletins have been posted today:

APSB15-09: Security updates available for Adobe Flash Player

APSB15-10: Security updates available for Adobe Reader and Acrobat

Customers of the affected products should consult the relevant Security Bulletin(s) for details.

This posting is provided “AS IS” with no warranties and confers no rights.

Upcoming Security Updates for Adobe Reader and Acrobat (APSB15-10)

A prenotification Security Advisory has been posted regarding upcoming Adobe Reader and Acrobat updates scheduled for Tuesday, May 12, 2015.

We will continue to provide updates on the upcoming release via the Security Advisory as well as the Adobe PSIRT blog.

This posting is provided “AS IS” with no warranties and confers no rights.

Adobe Security Bulletins Posted

The following Security Bulletins have been posted today:

APSB15-06: Security updates available for Adobe Flash Player

APSB15-07: Security update: hotfixes available for ColdFusion

APSB15-08: Security bulletin available for Adobe Flex

Customers of the affected products should consult the relevant Security Bulletin(s) for details.

This posting is provided “AS IS” with no warranties and confers no rights.

Security updates available for Adobe Flash Player (APSB15-05)

A Security Bulletin (APSB15-05) has been published regarding security updates for Adobe Flash Player.  These updates address critical vulnerabilities, and Adobe recommends users update their product installations to the latest versions using the instructions referenced in the security bulletin.

This posting is provided “AS IS” with no warranties and confers no rights.

Adobe Launches Web Application Vulnerability Disclosure Program on HackerOne

In recognition of the important role that independent security researchers play in keeping Adobe customers safe, today Adobe launches a web application vulnerability disclosure program on the HackerOne platform. Bug hunters who identify a web application vulnerability in an Adobe online service or web property can now privately disclose the issue to Adobe while boosting their HackerOne reputation score. We invite security researchers to view the disclosure guidelines available here: https://hackerone.com/adobe.

Adobe continues to welcome the coordinated disclosure of security issues affecting desktop products and enterprise on-premise solutions by notifying our Product Security Incident Response Team (PSIRT@adobe.com).

Pieter Ockers
Security Program Manager, PSIRT

Security updates available for Adobe Flash Player (APSB15-04)

A Security Bulletin (APSB15-04) has been published regarding security updates for Adobe Flash Player. These updates address CVE-2015-0313, which is being actively exploited in the wild via drive-by-download attacks against systems running Internet Explorer and Firefox on Windows 8.1 and below.

Adobe recommends users update their product installations to the latest versions using the instructions referenced in the security bulletin.

This posting is provided “AS IS” with no warranties and confers no rights.

UPDATED: Security Advisory for Adobe Flash Player (APSA15-02)

A Security Advisory (APSA15-02) has been published regarding a critical vulnerability (CVE-2015-0313) in Adobe Flash Player 16.0.0.296 and earlier versions for Windows, Macintosh and Linux.  We are aware of reports that this vulnerability is being actively exploited in the wild via drive-by-download attacks against systems running Internet Explorer and Firefox on Windows 8.1 and below.

UPDATE (February 4): users who have enabled auto-update for the Flash Player desktop runtime will be receiving version 16.0.0.305 beginning on February 4. This version includes a fix for CVE-2015-0313. Adobe expects to have an update available for manual download on February 5, and we are working with our distribution partners to make the update available in Google Chrome and Internet Explorer 10 and 11.

UPDATE (February 5): A Security Bulletin (APSB15-04) has been published regarding security updates for Adobe Flash Player. These updates address CVE-2015-0313.  Please refer to this post for more details. 

This posting is provided “AS IS” with no warranties and confers no rights.