Zero-day discovered by FireEye researchers allows RCE

May 12, 2016 23:35 GMT  ·  By

As it promised on Tuesday, Adobe released today a patch to fix several security-related problems with its Adobe Flash Player. Users are encouraged to download the company's latest Flash version which is now v21.0.0.242.

Two days ago, when Microsoft released its monthly Patch Tuesday security fixes for Windows, Adobe also announced that it was also preparing a new wave of updates, but that they were scheduled for Thursday.

The company took the time to put out this announcement just to draw attention to a zero-day exploit (CVE-2016-4117) discovered by security researcher Genwei Jiang from FireEye.

Thursday is here, and Adobe delivered on its promise, releasing its monthly security patch that also included fixes for 25 security issues, including the zero-day.

Last month, in April, Adobe also pre-announced and patched a similar Flash zero-day that allowed attackers to deliver the Cerber and Locky ransomware families.

Earlier on Tuesday, the company also addressed three security issues in ColdFusion, and another 92 security bugs in Adobe Acrobat and Reader.

Adobe Flash Player installed with Google Chrome, Microsoft Edge, and Internet Explorer (for Windows 10) will be updated to the latest version automatically.

Updates for Flash running on Windows, Mac, and Linux have been released and are available for download. The latest Adobe Flash Player version numbers are 21.0.0.242 for Windows and Mac, and 11.2.202.621 for Linux distros.