Skip to main content

Adobe issues patch for ‘critical’ vulnerability that could crash your computer

adobe finds another critical flaw in flash stock scott braut
Image used with permission by copyright holder
Another security vulnerability has been identified and patched in Adobe Flash but there have been no reports of the bug being exploited.

The vulnerability, CVE-2016-4117, which was deemed critical, was identified by FireEye engineer Genwei Jiang. On May 10, Adobe publicly acknowledged the bug, which affected Windows, Mac, Chrome OS, and Linux devices.

“Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system,” it said in its advisory.

No specific details about how the flaw could have been used were made public but Adobe bugs are rather frequently spotted and have been exploited plenty of times in the past. Security expert Graham Cluley expects that this latest flaw was used in malvertising or watering hole attacks via the Angler Exploit Kit. Ads that contain malicious code are a common method of burrowing into a system.

Adobe Flash is still widely used on many computers and this continues to pose a serious threat to users, said ESET U.K. security specialist Mark James.

“The program itself is one of many that users will leave on their machine without actually using it or understanding the security risk,” he said.

All users are advised to check that they are now running the latest version of the software to avoid any issues.

Common security vulnerabilities in Adobe Flash are a regular bugbear for the security community. Last year, Facebook’s chief security officer Alex Stamos called on Adobe to put a plan in place for calling time on Flash once and for all. Mozilla even took the step of blocking Flash by default in response to a series of zero days (previously undiscovered bugs) that emerged in quick succession.

Most recently, Adobe issued an emergency patch in early April after it was discovered that Flash left computers susceptible to ransomware attacks, the sort of malware that encrypts all your files and holds them for ransom, usually involving a payment of a couple of hundred dollars.

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
Hurry! The Razer Blade 17 gaming laptop is 44% off today
Cyberpunk 2077 running on the Razer Blade 17.

Razer is currently running a huge sale which includes one of the best gaming laptop deals we’ve seen in a while. Today, you can buy the Razer Blade 17 for 44% off bringing the price down from $3,800 to $2,100. This is a great price for an equally great gaming laptop and sure to appeal to anyone seeking great laptop deals. If you’re keen to learn more about it, keep reading while we take you through why it’s worth your money.

Why you should buy the Razer Blade 17
Razer is one of the best gaming laptop brands out there. Crucially, it’d likely top the list if it wasn’t that its laptops are frequently expensive so when one is on sale, it shoots right up the list of brands to check out. That’s because Razer laptops are stylish, slimmer than most, while still packing plenty of power.

Read more
How to download Vimeo videos on desktop and mobile
Vimeo app icon on Apple TV.

Downloading Vimeo videos lets you enjoy these high-quality, cinematic uploads without relying on an internet connection. These days, it’s easier than ever before to obtain these media files, too. Thanks to online video converters, you’ll be able to download and save videos straight to your smartphone, tablet, or laptop. There’s also the possibility you’ll just be able to download a video directly from Vimeo, without using extra software.

Read more
I finally found a gaming laptop utility that’s actually worth using
The Asus ROG Zephyrus G16 sitting on a coffee table.

Nearly all gaming laptops come with bundled first-party software, and most of it isn't all that good. They tend to be poorly designed and riddled with bloatware and features that you'll never need. Armoury Crate is Asus' version of that, and while it isn't terrible, it suffers from many of those same problems.

A large number of users on Reddit have voiced their criticism of Armoury Crate, accusing it of being buggy, broken, and overly complex. Some of the most common issues include the software's cluttered user interface, promotional pop-ups, unnecessary bloatware, and the high usage of system resources. In my experience, I do find Armoury Crate's UI to be confusing, and I've also noticed that the software runs way too many background processes and services, some of which seem unnecessary.

Read more