Headline
CVE-2016-4126: Adobe Security Bulletin
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Release date: June 16, 2016
Vulnerability identifier: APSB16-23
Priority: 3
CVE number: CVE-2016-4126
Platform: Windows
Adobe has released a security update for Adobe AIR for Windows. This update addresses a vulnerability in the directory search path used by the AIR installer that could potentially allow an attacker to take control of the affected system.
- To verify the version of Adobe AIR installed on your system, follow the instructions in the Adobe AIR TechNote.
Adobe categorizes this update with the following priority rating and recommends users update their installation to the newest version:
Adobe recommends users of the AIR desktop runtime, AIR SDK and AIR SDK & Compiler update to version 22.0.0.153 by visiting the AIR download center or the AIR developer center.
This update resolves a vulnerability in the directory search path used by the Air installer that could lead to code execution (CVE-2016-4126).
Adobe would like to thank Alec Blance for reporting this issue and for working with Adobe to help protect our customers.