CERT-In Vulnerability Note
CIVN-2016-0320
Microsoft Update for Vulnerabilities in Adobe Flash Player
Original Issue Date:December 14, 2016
Severity Rating: HIGH
Software Affected
- Windows 8.1 for 32-bit Systems
- Windows 8.1 for x64-based Systems
- Windows Server 2012
- Windows Server 2012 R2
- Windows RT 8.1
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 10 Version 1511 for 32-bit Systems
- Windows 10 Version 1511 for x64-based Systems
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows Server 2016 for 64-bit Systems
Overview
Multiple vulnerabilities have been reported in Adobe Flash Player when installed in windows operating system which could allow a remote attacker to execute arbitrary code and bypass security controls on the target system.
Description
These vulnerabilities are caused due to various use after-free-memory errors, memory corruption errors, and buffer overflow conditions. A remote attacker could exploit these vulnerabilities by creating specially crafted Flash content and convincing the target user to open the malicious file.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code and bypass security restrictions on the target system.
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS16-154
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/library/security/ms16-154.aspx
References
Adobe
https://helpx.adobe.com/security/products/flash-player/apsb16-39.html
Security Tracker
http://securitytracker.com/id/1037449
Cisco
https://tools.cisco.com/security/center/viewAlert.x?alertId=52078
CVE Name
CVE-2016-7867
CVE-2016-7868
CVE-2016-7869
CVE-2016-7870
CVE-2016-7871
CVE-2016-7872
CVE-2016-7873
CVE-2016-7874
CVE-2016-7875
CVE-2016-7876
CVE-2016-7877
CVE-2016-7878
CVE-2016-7879
CVE-2016-7880
CVE-2016-7881
CVE-2016-7890
CVE-2016-7892
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|