Adobe Flash Player version 30.0.0.113 available

Sicherheit[German]Adobe has released an update for the Flash Player on June 7, 2018, which upgrades it to version 30.0.0.113. Additions: The information is now available – Adobe has closed a critical zero-day vulnerability that could be exploited by Office files and was also exploited in the wild under Windows via Office files. Addendum: Microsoft has released update KB4287903 for Windows.


Advertising

No information from Adobe so far

There is no information on the new build from Adobe yet, the latest security bulletin APSB18-16 still refers to the May update. A German blog reader noticed me, that he got a Flash update within his Slimjet browser. I just checked the current Google Chrome, Adobe Flash Player version 30.0.0.113 is already installed there.

Version 30 indicates that this is a new development branch, because we were previously on Adobe Flash 29.x.x. The fact that this update is out of order (regularly I would have expected it on June 12, 2018) could indicate a security problem.

Addendum: Zero-Day vulnerability CVE-2018-5002 closed

Adobe has closed a zero-day vulnerability that could be exploited through office files. The vulnerability was discovered by several security providers (ICEBRG, Tencent, and two security departments of the Chinese security provider Qihoo 360). Adobe has published a security advisory APSB18-19, which decribes the vulnerability CVE-2018-5002:

Adobe has released security updates for Adobe Flash Player for Windows, macOS, Linux and Chrome OS. These updates address critical vulnerabilities in Adobe Flash Player 29.0.0.171 and earlier versions.  Successful exploitation could lead to arbitrary code execution in the context of the current user.

Adobe is aware of a report that an exploit for CVE-2018-5002 exists in the wild, and is being used in limited, targeted attacks against Windows users. These attacks leverage Office documents with embedded malicious Flash Player content distributed via email.

Details may be read within Security Advisory APSB18-19, an update to version 30.0.0.113 is strongly advised.

Adobes Flash Player version 30.0.0.113

The following Flash versions are affected. Adobe Flash Player 30.0.0.113 is provided for Windows, Macintosh, Linux and Chrome OS platforms.


Advertising

Product Version Platform
Adobe Flash Player Desktop Runtime 29.0.0.171 and earlier versions Windows, Macintosh
Adobe Flash Player for Google Chrome 29.0.0.171 and earlier versions Windows, Macintosh, Linux and Chrome OS
Adobe Flash Player for Microsoft Edge and Internet Explorer 11 29.0.0.171 and earlier versions Windows 10 and 8.1
Adobe Flash Player Desktop Runtime 29.0.0.171 and earlier versions Linux

If you have activated the auto-update function of the Flash Player and installed the player separately, you should receive this update automatically. Otherwise download the new version from APSB 18-19. I assume that the Flash Player for Windows 8.1 and Windows 10 will also be updated promptly by Microsoft (but no later than June 12, 2018).

Check for update in Google Chrome and Slimjet

Chrome Browser and Slimjet browser should automatically install the update. You can also check for updates manually by typing chrome://components in the browser's address bar.

Flash Player Version 30.0.0.113 im Chrome-Browser

Above is my German Google Chrome (also Slimjet browser), which reports, that version 30.0.0.113 is installed.

This Adobe website shows me version 30.0.0.113 as current for the Flash-Player. The previously available information, which Flash version is installed in the browser,is missing however. I guess, this is because the Chrome browser already blocks Flash by default. This is exactly what Adobe's Flash test tells me.

Flash Player

If you upgrade the Flash Player to version 30.0.0.113 via this Adobe website (the version is already available there), make sure that the optional offerings (McAfee Security Scan Plus and True Key from Intel) are not installed.

Update KB4287903 for Windows

Microsoft has released security update KB4287903 to close the vulnerability for the following Windows versions:

  • Windows Server Version 1803,
  • Windows 10 Version 1803,
  • Windows Server 2016 Version 1709,
  • Windows 10 Version 1709
  • Windows 10 Version 1703
  • Windows Server 2016
  • Windows 10 Version 1607
  • Windows 10 (RTM)
  • Windows Server 2012 R2
  • Windows RT 8.1
  • Windows 8.1

This package is available via Windows Update, may be also downloaded via Microsoft Update-Katalog. If you choose a manual install, note the restrictions described in KB4287903. Also read ADV180014 for further details.

Addendum: It seems that some users are facing install issue with KB4287903, see my blog post Flash-Update KB4287903: Install issues with WSUS.


Cookies helps to fund this blog: Cookie settings
Advertising


This entry was posted in Security, Update and tagged , , . Bookmark the permalink.

2 Responses to Adobe Flash Player version 30.0.0.113 available

  1. guenni says:

    A user informed me, that Adobe AIR 30 is also affected – but I didn't find details.

  2. Shoko says:

    Yes, Adobe Air 30.0.0.107 was released but there seems to be an issue with the update breaking the VUDU app that allows users to download and stream movies.

Leave a Reply

Your email address will not be published. Required fields are marked *