Flash Player is a relatively old plug-in (January 1996), it has become increasingly susceptible to malware. As a result, most web browsers have even started disabling Flash Player content by default for security reasons. The problem is not necessarily Flash Player itself, but some malware is added into a seemingly harmless Adobe Flash Player. ActionScript ® 3.0 Reference for the Adobe ® Flash ® Platform Home Show Packages and Classes List Hide Packages and Classes List Packages Classes What's New Index Appendixes. AIR internally uses a shared codebase with the Flash Player rendering engine and ActionScript 3.0 as the primary programming language. Applications must specifically be built for AIR to use additional features provided, such as multi-touch, file system integration, native client extensions, integration with Taskbar or Dock, and access to.
This information was sent to IT staff groups via email on May 13, 2015, with an update on May 27, 2015.
This message is intended for U-M IT staff who are responsible for maintaining and running university machines that have Adobe Flash Player and/or Adobe AIR products installed.
May 27 Update: Adobe Flash Player vulnerability CVE-2015-3090 is now being actively exploited. Unpatched machines can be compromised in order to deliver malware. Update affected machines as soon as possible. MiWorkspace-managed machines have been patched and are no longer at risk.
Summary
On May 12, Adobe released another set of security updates for Adobe Flash Player and AIR products for Windows, Macintosh and Linux. These updates address vulnerabilities that could potentially allow an attacker to take control of the affected system. Adobe recommends users update their product installations to the latest versions.
Affected Versions
- Adobe Flash Player 17.0.0.169 and earlier versions
- Adobe Flash Player 13.0.0.281 and earlier 13.x versions
- Adobe Flash Player 11.2.202.457 and earlier 11.x versions
- AIR Desktop Runtime 17.0.0.144 and earlier versions
- AIR SDK and SDK & Compiler 17.0.0.144 and earlier versions
Action Items
Update Adobe Flash Player to the latest version by visiting Adobe Flash Player Download Center. Update Adobe AIR products by visiting Adobe AIR Download Center.
- Windows and Mac: Update to Adobe Flash Player 17.0.0.188.
- Linux: Update to Adobe Flash Player 11.2.202.460.
- Google Chrome: Will automatically update to version 17.0.0.188.
- Internet Explorer on Windows 8.x: Will automatically update to version 17.0.0.188.
- Extended Support Release: Update to version 13.0.0.289 by visiting Archived Flash Player Versions.
- Adobe AIR desktop runtime: Update to version 17.0.0.172.
- Adobe AIR SDK and AIR SDK & Compiler: Update to version 17.0.0.172.
Information for Users
MiWorkspace machines will be updated today, May 13. If you have Adobe Flash Player installed on your own devices that are not managed by the university, please update by visiting the Adobe Flash Player Download Center.
In general, the best protection for your devices is this: keep your software and apps up-to-date, do not click suspicious links in email, do not open email attachments unless you are expecting them and trust the person who sent them, and only use secure, trusted networks. For more information, see Spam, Phishing, and Suspicious Email,Instructions for Securing Your Devices and Data, and Use a Secure Internet Connection.
Questions, Concerns, Reports
Please contact iia.inform@umich.edu.
Sincerely,
ITS Information and Infrastructure Assurance
References
Adobe Air Flash Player
- Adobe Security Bulletin (Adobe, 5/12/15)
- Adobe, Microsoft Push Critical Security Fixes (Krebs on Security, 5/12/15)
- Angler EK Exploiting Adobe Flash CVE-2015-3090 (FireEye, 5/26/15)