Adobe updates Shockwave for critical flaw
Adobe is advising users of its Shockwave player to update to a new version to protect against a critical remotely exploitable flaw.
The flaw affects Adobe Shockwave Player
18.104.22.1686 and earlier versions and according to Adobe's advisory, "... could allow an
attacker who successfully exploits this vulnerability to take control
of the affected system."
Adobe's new Shockwave Player 22.214.171.1240 corrects the issue, though it requires users to uninstall their existing Shockwave player first.
First off all, the flaw was responsibly disclosed first by way of the Tipping Point Zero Day Initiative (ZDI). The way that works is, ZDI pays the researcher for the flaw and then ZDI keeps the details under wraps until a fix exists.