A critical vulnerability (CVE-2016-1019) exists in Adobe Flash Player 126.96.36.199 and earlier versions for Windows, Macintosh, Linux, and Chrome OS. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.
Adobe is aware of reports that CVE-2016-1019 is being actively exploited on systems running Windows 7 and Windows XP with Flash Player version 188.8.131.526 and earlier. A mitigation introduced in Flash Player 184.108.40.206 currently prevents exploitation of this vulnerability, protecting users running Flash Player 220.127.116.11 and later.
Adobe is planning to provide a security update to address this vulnerability as early as April 7.
Critical Flash Player leak to be plugged on Thursday
Posted on Wednesday, Apr 06 2016 @ 13:32 CEST by Thomas De Maesschalck