A new update to has been released for Adobe Flash. According to Adobe this is a “These updates address a critical (http://www NULL.adobe NULL.com/support/security/severity_ratings NULL.html) vulnerability in the software”.
These updates address an object confusion vulnerability (CVE-2012-0779) that could cause the application to crash and potentially allow an attacker to take control of the affected system. There are reports that the vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious file delivered in an email message. The exploit targets Flash Player on Internet Explorer for Windows only.
The update has been released for Windows, Mac, Linux and Android. Currently the exploit that has been fix only seems to target Internet Explorer for Windows, but EVERYONE should update their version of Flash. Once the fix is released, the bad guys can compare the old and new versions of the software and find where the problems are.
In addition, if you are a Windows user who is thinking “I don’t use Internet Explorer it doesn’t affect me”, you are WRONG. You need to update your copy of Flash for Internet Explorer and your copy of Flash for the browser you do use (IE – Firefox). The fact that Internet Explorer is loaded on your pc affects you, even if you are not using it.
This update is important because the exploit gives the bad guys a way in to your pc. If you imagine your house having the lock to one of your doors broken, and you not doing anything about it, and then when someone gets in and steals from you wondering how you got robbed. This is the computer equivalent to that.
Addition details can be found on the (LINK) Adobe Security Bulletin (https://www NULL.adobe NULL.com/support/security/bulletins/apsb12-09 NULL.html)
Affected software
Flash Player 11.2.202.233 and earlier
Recommended player update
11.2.202.235
Availability
Flash Player Download Center (http://www NULL.adobe NULL.com/go/getflash)
