Adobe Patch Day Consists of Minor Flash Update

Adobe shares Microsoft’s Patch Day, and they usually release a handful of security updates themselves. However, this month they’ve kept it pretty simple, with only one relatively minor update for their Flash Player.

According to their bulletin, the latest Flash update fixes two security flaws in their popular web-based media player. Adobe is never one to share much detail about their vulnerabilities, but they do share the impact of each of these flaws.  They mention one of the flaws allows attackers to bypass the same origin policy, while the other allows attackers to read the contents of your computer’s clipboard. Compared to Adobe’s recent emergency Flash patch, which fixed a zero day issue exploited in the wild, these issues are not very severe. In fact, Adobe only assigns them a priority (severity) rating of 2, which means you should think about updating in the next 30 days.

Nonetheless, it doesn’t hurt to update your client computers, and Adobe’s automatic updater should make it pretty easy. If you aren’t already letting Adobe get it’s automatic updates, at least on client machines, I recommend you do so. — Corey Nachreiner, CISSP (@SecAdept

About Corey Nachreiner

Corey Nachreiner has been with WatchGuard since 1999 and has since written more than a thousand concise security alerts and easily-understood educational articles for WatchGuard users. His security training videos have generated hundreds of letters of praise from thankful customers and accumulated more than 100,000 views on YouTube and Google Video. A Certified Information Systems Security Professional (CISSP), Corey speaks internationally and is often quoted by other online sources, including C|NET, eWeek, and Slashdot. Corey enjoys "modding" any technical gizmo he can get his hands on, and considers himself a hacker in the old sense of the word.

Trackbacks/Pingbacks

  1. Shockwave Update Misses Adobe Patch Day | WatchGuard Security Center - March 13, 2014

    […] few days ago, I posted an alert mentioning how Adobe Patch Day was particularly light, and pointing out the one minor Flash Player […]

  2. NSA’s Turbine – WSWiR Episode 98 | WatchGuard Security Center - March 14, 2014

    […] March Flash Bulletin – WGSC […]

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

%d bloggers like this: