Описание
February 2018 Adobe Flash Security Update
This security update addresses the following vulnerabilities, which are described in Adobe Security Bulletin APSB18-03: CVE-2018-4877 and CVE-2018-4878.
FAQ
How could an attacker exploit these vulnerabilities? In a web-based attack scenario where the user is using Internet Explorer for the desktop, an attacker could host a specially crafted website that is designed to exploit any of these vulnerabilities through Internet Explorer and then convince a user to view the website. An attacker could also embed an ActiveX control marked "safe for initialization" in an application or Microsoft Office document that hosts the IE rendering engine. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit any of these vulnerabilities. In all cases, however, an attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically by clicking a link in an email message or in an Instant Messenger message that takes users to the attacker's website, or by opening an attachment sent through email.
In a web-based attack scenario where the user is using Internet Explorer in the Windows 8-style UI, an attacker would first need to compromise a website already listed in the Compatibility View (CV) list. An attacker could then host a website that contains specially crafted Flash content designed to exploit any of these vulnerabilities through Internet Explorer and then convince a user to view the website. An attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically by clicking a link in an email message or in an Instant Messenger message that takes users to the attacker's website, or by opening an attachment sent through email. For more information about Internet Explorer and the CV List, please see the MSDN Article, Developer Guidance for websites with content for Adobe Flash Player in Windows 8.
Обновления
Продукт | Статья | Обновление |
---|---|---|
Adobe Flash Player on Windows 10 Version 1703 for 32-bit Systems | ||
Adobe Flash Player on Windows 10 Version 1703 for x64-based Systems | ||
Adobe Flash Player on Windows 10 Version 1709 for 32-bit Systems | ||
Adobe Flash Player on Windows 10 Version 1709 for x64-based Systems | ||
Adobe Flash Player on Windows 10 for 32-bit Systems | ||
Adobe Flash Player on Windows 10 for x64-based Systems | ||
Adobe Flash Player on Windows 10 Version 1511 for 32-bit Systems | ||
Adobe Flash Player on Windows 10 Version 1511 for x64-based Systems | ||
Adobe Flash Player on Windows 10 Version 1607 for 32-bit Systems | ||
Adobe Flash Player on Windows 10 Version 1607 for x64-based Systems |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited