Windows 10 systems getting the patch too

Mar 11, 2016 22:41 GMT  ·  By

Microsoft has just rolled out an emergency update for Windows systems that comes to correct Flash Player security flaws already fixed by Adobe with version 21.0.0.182.

Since Windows 8, Flash Player is directly integrated into Internet Explorer, so when Adobe rolls out new updates to patch security fixes, Microsoft has to issue its very own update addressed to Windows computers. Windows 10 makes no exception to this new rule, as Flash Player is also built into Internet Explorer 11 and Microsoft Edge browser.

So following the latest update released by Adobe to patch 18 security vulnerabilities in Flash Player, Microsoft has also rolled out its very own update aimed at Windows systems containing the same fixes.

The update is shipped as we speak to computers running Windows 7, 8/8.1, and Windows 10, and everyone is recommended to install it as soon as possible because it fixes critical flaws in Flash Player.

One publicly exploited security hole

What’s worse, one of the security holes that Adobe (and now Microsoft) is patching with this update is already being exploited in the wild. Flash Player is currently installed on millions of computers out there, so a security flaw can be easily exploited using a compromised website, with Adobe warning that an attacker can get control of a vulnerable system in case the patch is not deployed.

“Adobe has released security updates for Adobe Flash Player. These updates address critical vulnerabilities that could potentially allow an attacker to take control of the affected system. Adobe is aware of a report that an exploit for CVE-2016-1010 is being used in limited, targeted attacks,” the company says in an advisory rolled out today.

As usual, the new patch is shipped to Windows computers via Windows Update, and a reboot is not required, so both consumers and IT admins could start deployment as soon as possible, especially because their work won’t be interrupted (rebooting the browser will, however, be needed).