This article is more than 1 year old
Hackers exploit fresh PC hijack bug in Adobe Flash Player, the internet's screen door
Patch now, or just dump the thing
Adobe is advising users and administrators to patch its Flash Player after yet another remote-code execution vulnerability was discovered in the plugin.
The patch fixes bug CVE-2015-3113, which allows attackers to take control of a system if it opens a malicious Flash file. Miscreants are exploiting the flaw in the wild to hijack PCs, targeting Internet Explorer on Windows 7 and Firefox on Windows XP.
Adobe credited researchers at FireEye in spotting and reporting the flaw. Miscreants are apparently spamming out links in emails to websites hosting malicious Flash files that exploit the vulnerability.
For Windows and OS X, the updated version will be Flash Player 184.108.40.206. On Linux the Patch version is 220.127.116.118, and for Flash Player Extended Support, the latest is 18.104.22.1686. The patch is being considered a top priority install on both Windows and OS X, with Linux at a lower risk.
Users of Chrome, and Windows 8 users running Internet Explorer, will automatically receive the updated version. For those on other browsers, Adobe recommends installing the patch as soon as possible.
Security researchers have an alternative solution to offer users: dump Flash.
"In lieu of patching Flash Player yet again, it might be worth considering whether you really need to keep Flash Player installed at all," wrote security journalist Brian Krebs.
Adobe release critical patch for Flash. Update now or take this as an opportunity to uninstall. #infosec https://t.co/cDmGprofjj— Gavin Millard (@gmillard) June 23, 2015
Those who wish to stick with Flash Player can get the patched versions from Adobe's download page. ®