Description:
Security updates are released for Adobe Flash Player and Adobe Reader/Acrobat to address multiple vulnerabilities. To exploit the vulnerabilities, a remote attacker would entice a targeted user to open a specially crafted PDF file, web page, Flash file, or document that supports embedded Flash content.
Affected Systems:
- Adobe Flash Player Desktop Runtime for Windows, Macintosh and Linux 27.0.0.183 and earlier versions
- Adobe Flash Player for Google Chrome 27.0.0.183 and earlier versions
- Adobe Flash Player for Microsoft Edge and Internet Explorer 11 27.0.0.183 and earlier versions
- Adobe Acrobat/Acrobat Reader 2017 2017.011.30066 and earlier versions
- Adobe Acrobat DC/Acrobat Reader DC Continuous 2017.012.20098 and earlier versions
- Adobe Acrobat DC/Acrobat Reader DC Classic 2015.006.30355 and earlier versions
- Adobe Acrobat/Reader XI 11.0.22 and earlier versions
Impact:
A successful exploitation could lead to arbitrary code execution, information disclosure, excessive resource consumption, drive-by-download or attackers' control of the affected system.
Recommendation:
Upgrade Adobe Flash Player and Adobe Reader/Acrobat to the following versions to address the issues. The upgrade can be obtained by using the auto-update mechanism or by downloading at the following URLs:
- Adobe Flash Player Desktop Runtime 27.0.0.187 for Windows and Macintosh
https://get.adobe.com/flashplayer
http://www.adobe.com/products/players/flash-player-distribution.html
- Adobe Flash Player 27.0.0.187 for Google Chrome
https://chromereleases.googleblog.com/
- Adobe Flash Player 27.0.0.187 for Microsoft Edge and Internet Explorer 11
https://portal.msrc.microsoft.com/en-US/security-guidance
- Adobe Flash Player 27.0.0.187 for Linux
https://get.adobe.com/flashplayer/
- Adobe Acrobat DC Continuous 2018.009.20044, Acrobat DC Classic 2015.006.30392, Acrobat 2017 2017.011.30068, Acrobat Reader 2017 2017.011.30068, Acrobat XI 11.0.23<
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Mac
- Adobe Acrobat Reader DC Classic 2015.006.30392, Reader XI 11.0.23
http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Mac
- Adobe Acrobat Reader DC Continuous 2018.009.20044
http://get.adobe.com/reader/
If you have multiple browsers, you are required to perform the Adobe Flash Player upgrade for each browser. The Flash Player version can be checked using the following URL:
http://www.adobe.com/software/flash/about/
More Information:
https://helpx.adobe.com/security/products/acrobat/apsb17-36.html
https://helpx.adobe.com/security/products/flash-player/apsb17-33.html
https://www.hkcert.org/my_url/en/alert/17111502
https://www.us-cert.gov/ncas/current-activity/2017/11/14/Adobe-Releases-Security-Updates
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3112
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3114
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11213
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11215
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11225
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11293
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16360 (to CVE-2017-16420)