Operating System:

[WIN]

Published:

13 September 2018

Protect yourself against future threats.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2018.0217
            Microsoft Updates for Adobe Flash Player on Windows
                             13 September 2018

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Adobe Flash Player
Operating System:     Windows
Impact/Access:        Access Confidential Data -- Remote with User Interaction
Resolution:           Patch/Upgrade
CVE Names:            CVE-2018-15967  
Member content until: Saturday, October 13 2018
Reference:            ESB-2018.2731

OVERVIEW

        Microsoft has released its monthly security patch updates for Adobe 
        Flash Player on Microsoft Windows for the month of September 2018. [1]
        
        Windows 8.1 for 32-bit systems
        Windows 8.1 for x64-based systems
        Windows Server 2012
        Windows 10 Version 1607 for x64-based Systems
        Windows 10 Version 1607 for 32-bit Systems
        Windows 10 for x64-based Systems
        Windows Server 2012 R2
        Windows 10 for 32-bit Systems
        Windows RT 8.1
        Windows Server 2016
        Windows 10 Version 1703 for x64-based Systems
        Windows 10 Version 1703 for 32-bit Systems
        Windows 10 Version 1709 for 32-bit Systems
        Windows 10 Version 1709 for 64-based Systems
        Windows 10 Version 1803 for 32-bit Systems
        Windows 10 Version 1803 for x64-based Systems


IMPACT

        The details regarding these vulnerabilities are found from the 
        September Flash Security Update in Adobe Security Bulletin ADV180023
        for the following CVE:
        
        CVE-2018-15967 [2]


MITIGATION

        Microsoft recommends updating the software with the version made 
        available on the Microsoft Update Cataloge for KB4457146. [3]


REFERENCES

        [1] Security Update Guide
            https://portal.msrc.microsoft.com/en-us/security-guidance

        [2] September 2018 Adobe Flash Security Update
            https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180023

        [3] KB4457146
            https://support.microsoft.com/help/4457146

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBW5oAq2aOgq3Tt24GAQhf6BAAg9jvg4yhDIIYCXLPO0AmxI55JD9GUM2O
zYrzulHkakaSA7FZtEcduirzD3TauXUNootfoCcQ/9cohsA5Q3M0l7wpwdqhMQYy
pbGE8TLnaSIJUemGvhj+a9T887YdayeT3M8GyY6QU8CGhkJcTHz95p++s/BijJ2A
Uc+lHtphFLDW0YN0xqCkHDB6O/navdcGyfzeRf9+Ha4u3qjfeae0mfS17yxYcJTb
a3JX3f6E6vQwAV7Cy48JmqsSykacDP6qdDgQf1+qcz2bspk/myv4X7C0UUg0RrKv
Gyf4FK9KenBS94TyNgwWipHoOJznCsblWLQxpT6m9mzg0K/uS59ut1pzAgCrv8ST
N5xMyhFCPhcFmSms6IrEcupk7Vcl5R0/WqULmjpy1Lrt7vR+E6rcdJnsEhyFeL21
v+zp0N2zXmcf3U6pyvKoWdgSE7W6hu/2QLSLaWG7HP8LmUHs48UX/4HWDhC+gP8B
WVqVD5PtrMOlLinXEVnNu5Bx6cJVj+xFvUoWKI4u+eXBPIFaZ/xNb0ZTk2PHlSJu
LJrWAzRvdPJ/WX3AlaMp8C2X5RKUsLFih5za7VH/Evu0wDVCEKu4DTsaoMN3Qfe/
4LcEpw4XkBXrEZxn2nhXvyvNNmbvJW0ha3lX0aTNaqHszHyn9O5JCpJQs363Juns
nXGD8f+fwI8=
=C4CW
-----END PGP SIGNATURE-----