Catalin Cimpanu at BleepingComputer has a worrisome post. Apparently the South Korean version of CERT, KR-CERT, has found a Flash 0day that’s in the w
[See the full post at: New Flash zero-day]
![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
New Flash zero-day
Home » Forums » Newsletter and Homepage topics » New Flash zero-day
- This topic has 31 replies, 12 voices, and was last updated 7 years, 2 months ago.
Tags: Flash 0day
Viewing 13 reply threadsAuthorReplies-
Geo
AskWoody Plus -
Kirsty
ManagerFebruary 1, 2018 at 3:19 pm #163860It may be worth noting that this vulnerability affects the “current” version of Flash. Even if you updated this month, that won’t give you any help – until a fix is released (that may possibly be a couple of weeks away, as Catalin mentioned).
3 users thanked author for this post.
-
L95
AskWoody PlusFebruary 1, 2018 at 4:10 pm #163867With regard to how to turn off Adobe Flash, Woody’s posting has a link to an article by Tom Wagenseil. That article appears to be over a year old, and I think it might be outdated with respect to how to turn off Adobe Flash in the Google Chrome browser. If you have trouble with the procedure in that article with respect to Chrome, you might want to go to the following link https://productforums.google.com/forum/#!topic/chrome/1VNwlragY-s and scroll down to the “Best Answer” on that page to see a more updated procedure for disabling Flash. At least that’s the procedure that I’ve been using for the past year or so, whereas in prior years I used procedure described in the Tom Wagenseil article.
-
Ascaris
AskWoody MVPFebruary 1, 2018 at 8:09 pm #163911I’ve had Flash uninstalled from my PCs for a while now. It was not that long ago that having no Flash was a serious impediment, but HTML5 has risen to fill the void for the vast majority of sites. Every now and then I get a link to some site (Vimeo, I think), and it tells me that “[my] technology may be out of date” because I don’t have Flash installed. You’re pushing Flash videos and I’m the one whose tech is out of date?
Fortunately, by clicking the video and going to the site directly, it then works with HTML5; it just doesn’t work embedded that way.
Flash has never managed to get its act together and become a secure product. Like Java, it’s just a great big security sieve, and because of that, we’re all better off without it. If you have no sites that you use that specifically require Flash, I would just remove it; otherwise, in Firefox, you can set the plugin to “Ask to activate” or “Never activate.” You can always manually turn it on for those few sites that still need it.
For me, the US National Weather Service site is the only one I use regularly that still wants Flash (for the radar animations). Not really a problem; there are lots of weather sites that provide radar data better than NWS that don’t try to get me to install and use an unsafe plugin.
Dell XPS 13/9310, i5-1135G7/16GB, KDE Neon 6.2
XPG Xenia 15, i7-9750H/32GB & GTX1660ti, Kubuntu 24.04
Acer Swift Go 14, i5-1335U/16GB, Kubuntu 24.04 (and Win 11)1 user thanked author for this post.
-
OscarCP
MemberFebruary 1, 2018 at 11:04 pm #163926I believe that people who stream movies and TV shows from Hulu still need to use flash to do that, and I wonder which other similar services also widely used might be still requiring Flash to watch. There is a general move towards HTML5 these days, but at different stages at different streaming services. There is a similar situation with Java, that is still required by some useful Web sites (I am thinking of some publicly available online government services, such as those of NOAA where one can download USA atmospheric and GPS data).
Ex-Windows user (Win. 98, XP, 7); since mid-2017 using also macOS. Presently on Monterey 12.15 & sometimes running also Linux (Mint).
MacBook Pro circa mid-2015, 15" display, with 16GB 1600 GHz DDR3 RAM, 1 TB SSD, a Haswell architecture Intel CPU with 4 Cores and 8 Threads model i7-4870HQ @ 2.50GHz.
Intel Iris Pro GPU with Built-in Bus, VRAM 1.5 GB, Display 2880 x 1800 Retina, 24-Bit color.
macOS Monterey; browsers: Waterfox "Current", Vivaldi and (now and then) Chrome; security apps. Intego AV -
Scribe
AskWoody LoungerFebruary 2, 2018 at 3:23 am #163949In Firefox, Flash is already set to Ask to Activate by default. It can also be disabled in the Add-ons Manager (Ctrl+Shift+A) > Plugins.
EOL schedule – https://developer.mozilla.org/en-US/docs/Plugins/Roadmap
-
Kirsty
ManagerFebruary 2, 2018 at 10:51 pm #164232Attackers Exploiting Unpatched Flaw in Flash
By Brian Krebs | February 2, 2018
Adobe said a critical vulnerability (CVE-2018-4878) exists in Adobe Flash Player 28.0.0.137 and earlier versions. Successful exploitation could allow an attacker to take control of the affected system.The software company warns that an exploit for the flaw is being used in the wild, and that so far the attacks leverage Microsoft Office documents with embedded malicious Flash content. Adobe said it plans to address this vulnerability in a release planned for the week of February 5.
Read the full article here, which includes tips on hobbling Flash, like:“Another, perhaps less elegant, alternative to wholesale kicking Flash to the curb is to keeping it installed in a browser that you don’t normally use, and then only using that browser on sites that require Flash.”
-
WildBill
AskWoody PlusFebruary 7, 2018 at 5:35 pm #165843As per Woody’s advice, I’ve turned off Flash in Firefox & IE. However, patching Flash is like patching IE; even if you don’t use it, it’s best to keep it updated. You mentioned “Adobe said it plans to address this vulnerability in a release planned for the week of February 5.” Just letting folks know today, KB4074595 appeared in Windows Update today, labeled “2018-02 Security Update for Adobe Flash Player”, & dated 02/06/18. For Windows 8.1; your numbering & mileage may vary. Is this the fix for the flaw? Even if it is & we are still at MS-DEFCON 3, should we rush to patch before Feb. 13?! Or should we hold off?
Bought a refurbished Windows 10 64-bit, currently updated to 22H2. Have broke the AC adapter cord going to the 8.1 machine, but before that, coaxed it into charging. Need to buy new adapter if wish to continue using it.
Wild Bill Rides Again... -
Kirsty
ManagerFebruary 7, 2018 at 5:55 pm #165845 -
WildBill
AskWoody PlusFebruary 7, 2018 at 7:27 pm #165858Thanks; I’ll probably do it through WU before MS-DEFCON goes back to 2 next week. Later tonight or tomorrow. Just for grins, though, I re-enabled Flash as Ask to Activate, then checked my Flash version for Firefox under Win 8.1. Adobe says it’s current at 28.0.0.161.
Bought a refurbished Windows 10 64-bit, currently updated to 22H2. Have broke the AC adapter cord going to the 8.1 machine, but before that, coaxed it into charging. Need to buy new adapter if wish to continue using it.
Wild Bill Rides Again...1 user thanked author for this post.
-
-
-
anonymous
Guestanonymous
GuestFebruary 3, 2018 at 4:56 am #164280@Woody I am wondering why you (only) gave the advice
“If you absolutely must use Flash on a specific site, first write to the site’s owners and complain loudly. Then, figure out which browser you want to use with Flash (I’ve picked Chrome) and only use that browser to go to the bad site”
and not to use a container like Sandboxie to keep yourself safe from Flash (and other) vulnerabilities?-
Kirsty
ManagerFebruary 3, 2018 at 1:24 pm #164376… that may be because sandboxing is no bullet-proof solution (I’ve found articles dating back to 2008, describing malware being able to fire in a sandbox, but this one is more current).
Malware like Dridex does not respect a sandbox:
Malwarebytes article discusses the Word document embedded in a .pdf (Dridex method), giving details of the exploits. It allows sandboxing to be bypassed!
The attack relies on users opening up malicious attachments that will appear legitimate. Many studies have shown that users are often the weakest link in an attack chain and criminals know that too well.
See: On proofpoint.com
and specific to Flash, last August, from threatpost.com
geekdom
AskWoody_MVPFebruary 3, 2018 at 10:59 am #164358Adobe Flash is disabled on everything, but this news provides a good reason to uninstall it and never, ever install it again. Fewer moving parts is a good concept.
On permanent hiatus {with backup and coffee}
offline▸ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offline▸ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
online▸ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefender-
Kirsty
Manager
anonymous
GuestFebruary 3, 2018 at 9:35 pm #164453The thing that bothers me about removing Flash is the archival, preservational aspect of the Internet. There previously were projects that tried to port Flash over to web-standards, but they all seem to have been abandoned.
A huge part of Internet standards is backwards compatibility. Even when things break, we tend to break them in a way that they’re still technically usable. Sure, there are old sites that still use old things like RealPlayer, but you can still ultimately play the files, and even convert them to modern formats that are safer.
But Flash is an outlier. Flash video can be converted, sure. But Flash interactivity cannot. As such, to view older content, I need to run Flash.
I hate that the answer will be to run an older web browser, with fewer security fixes and more trouble. My ideal choice for an answer would be to have all the content archived on something like archive.org, and Flash enabled there, possibly with some sort of security tokens that prevent hackers from modifying the site.
Yes, new content should not be made in Flash. But so much of web history is Flash-based. I hate losing it. And I will fight to try and preserve it however I have to.
-
Kirsty
ManagerFebruary 3, 2018 at 9:40 pm #164457A related topic, discussed last year:
https://www.askwoody.com/forums/topic/would-open-source-flash-player-be-safer/
Schnarph
AskWoody LoungerFebruary 4, 2018 at 12:33 am #164476But Flash is an outlier. Flash video can be converted, sure. But Flash interactivity cannot. As such, to view older content, I need to run Flash.
That’s the rub. I haven’t needed Flash or anything Adobe for years, but I know those that will truly miss Flash games. Some people have spent(wasted IMO) hundreds of hours on such games and have progress saved but only on the online websites. Is there any hope?
anonymous
Guestgeekdom
AskWoody_MVPFebruary 5, 2018 at 9:51 am #164845Warning: If you are looking to uninstall the Adobe Flash, it does not uninstall nicely. (The Adobe Acrobat Reader also does not uninstall nicely.)
On permanent hiatus {with backup and coffee}
offline▸ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offline▸ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
online▸ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefender-
Kirsty
Manager -
geekdom
AskWoody_MVPFebruary 5, 2018 at 12:53 pm #164924The uninstaller from Adobe was run several times yesterday on another system. The uninstaller from your link was run just now on a different system. In both cases, the uninstaller appears to work just fine. Here is the kicker:
- Make sure to exit Internet Explorer.
- Run uninstaller.
- Manually delete C:\Users\[Name]\AppData\Roaming\Adobe file folder.
- Start Internet Explorer.
- C:\Users\[Name]\AppData\Roaming\Adobe file folder appears again.
The uninstaller has failed to remove some portion of Flash that reactivates each time Internet Explorer is started.
This problem does not appear with Firefox.
On permanent hiatus {with backup and coffee}
offline▸ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offline▸ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
online▸ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefender -
Kirsty
ManagerFebruary 5, 2018 at 1:02 pm #164929I wonder if it relates to the WinOS? I am aware of long-standing issues with uninstalling, for which Adobe have been issuing manual uninstalltion instructions for ages.
-
geekdom
AskWoody_MVPFebruary 5, 2018 at 1:21 pm #164939The link you supplied just now is where I started yesterday. Both computer systems are:
- Windows 7
- 64-bit
I think the uninstaller has failed to clear registry entries.
On permanent hiatus {with backup and coffee}
offline▸ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offline▸ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
online▸ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefender1 user thanked author for this post.
-
Kirsty
ManagerFebruary 5, 2018 at 1:54 pm #164966While not being 100% similarity to your problem, there may be some suggestion/s in this answers.microsoft.com response that helps, i.e. being logged on as administrator?
-
geekdom
AskWoody_MVPFebruary 5, 2018 at 2:27 pm #164995I am logged on as administrator by default and the program was “run as administrator.” The problem persists. It is clear that the problem is on Adobe’s end.
On permanent hiatus {with backup and coffee}
offline▸ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offline▸ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
online▸ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefender -
Kirsty
Manager -
geekdom
AskWoody_MVPFebruary 5, 2018 at 3:53 pm #165047To set your mind at ease, I don’t run under built-in administrator. When I wish to “Run as administrator”, I right-click a program and select “run as administrator.”
To reiterate, I am sole user and owner, and am shown as administrator.
Revo Uninstaller was used; it is one of the tools in my toolkit.
The problem is Adobe’s.
On permanent hiatus {with backup and coffee}
offline▸ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offline▸ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
online▸ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefender1 user thanked author for this post.
-
Kirsty
ManagerFebruary 5, 2018 at 6:06 pm #165090While not everyone agrees about preferred user account privileges:
Of course, that is your own risk assessment to take 🙂
-
walker
AskWoody Lounger
-
-
-
Viewing 13 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Proton to drop prices after ruling against “Apple tax”
by
Cybertooth
5 hours, 30 minutes ago -
24H2 Installer – don’t see Option for non destructive install
by
JP
5 hours, 56 minutes ago -
Asking Again here (New User and Fast change only backups)
by
thymej
16 hours, 51 minutes ago -
How much I spent on the Mac mini
by
Will Fastie
6 hours, 18 minutes ago -
How to get rid of Copilot in Microsoft 365
by
Lance Whitney
8 hours, 39 minutes ago -
Spring cleanup — 2025
by
Deanna McElveen
22 hours, 43 minutes ago -
Setting up Windows 11
by
Susan Bradley
1 hour, 6 minutes ago -
VLC Introduces Cutting-Edge AI Subtitling and Translation Capabilities
by
Alex5723
18 hours, 11 minutes ago -
Powershell version?
by
CWBillow
19 hours, 4 minutes ago -
SendTom Toys
by
CWBillow
3 hours, 20 minutes ago -
Add shortcut to taskbar?
by
CWBillow
23 hours ago -
Sycophancy in GPT-4o: What happened
by
Alex5723
1 day, 15 hours ago -
How can I install Skype on Windows 7?
by
Help
1 day, 14 hours ago -
Logitech MK850 Keyboard issues
by
Rush2112
20 hours, 59 minutes ago -
We live in a simulation
by
Alex5723
2 days, 5 hours ago -
Netplwiz not working
by
RetiredGeek
1 day, 16 hours ago -
Windows 11 24H2 is broadly available
by
Alex5723
2 days, 17 hours ago -
Microsoft is killing Authenticator
by
Alex5723
1 day, 5 hours ago -
Downloads folder location
by
CWBillow
3 days ago -
Remove a User from Login screen
by
CWBillow
1 day, 19 hours ago -
TikTok fined €530 million for sending European user data to China
by
Nibbled To Death By Ducks
2 days, 15 hours ago -
Microsoft Speech Recognition Service Error Code 1002
by
stanhutchings
2 days, 15 hours ago -
Is it a bug or is it expected?
by
Susan Bradley
17 hours, 38 minutes ago -
Image for Windows TBwinRE image not enough space on target location
by
bobolink
2 days, 14 hours ago -
Start menu jump lists for some apps might not work as expected on Windows 10
by
Susan Bradley
1 day, 14 hours ago -
Malicious Go Modules disk-wiping malware
by
Alex5723
3 days, 4 hours ago -
Multiple Partitions?
by
CWBillow
3 days, 4 hours ago -
World Passkey Day 2025
by
Alex5723
1 hour, 56 minutes ago -
Add serial device in Windows 11
by
Theodore Dawson
4 days, 13 hours ago -
Windows 11 users reportedly losing data due forced BitLocker encryption
by
Alex5723
2 days, 14 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.