Product
Security update available for Adobe Shockwave Player
Release date: September 8, 2015
Vulnerability identifier: APSB15-22
Priority: See table below
CVE number: CVE-2015-6680, CVE-2015-6681
Platform: Windows
Summary
Adobe has released a security update for Adobe Shockwave Player. This update addresses critical vulnerabilities that could potentially allow an attacker to take control of the affected system.
Affected software versions
|
Affected versions |
Platform |
Adobe Shockwave Player |
12.1.9.160 and earlier |
Windows |
Solution
Adobe categorizes this update with the following priority rating and recommends users update their installation to the newest version by following the instructions below:
Updated version |
Platform |
Priority rating |
Availability |
|
Adobe Shockwave Player |
12.2.0.162 |
Windows |
1 |
Adobe recommends users of Adobe Shockwave Player 12.1.9.160 and earlier versions update to Adobe Shockwave Player 12.2.0.162 by visiting the Adobe Shockwave Player Download Center.
Vulnerability Details
This update resolves memory corruption vulnerabilities that could lead to code execution (CVE-2015-6680, CVE-2015-6681).
Acknowledgments
Adobe would like to thank Tongbo Luo of Palo Alto Networks for reporting these issues and for working with Adobe to help protect our customers.