header-logo
Suggest Exploit
vendor:
Flash Player
by:
Google Security Research
9,8
CVSS
CRITICAL
Heap Overflow
122
CWE
Product Name: Flash Player
Affected Version From: Prior to 32.0.0.255
Affected Version To: Prior to 32.0.0.255
Patch Exists: YES
Related CWE: CVE-2019-8069
CPE: o:adobe:flash_player
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2019

Adobe Flash Player MP4 Heap Overflow

A heap overflow vulnerability exists in Adobe Flash Player when processing MP4 files. An attacker can exploit this vulnerability to execute arbitrary code in the context of the current user.

Mitigation:

Upgrade to Adobe Flash Player version 32.0.0.255 or later.
Source

Exploit-DB raw data:

Source: https://code.google.com/p/google-security-research/issues/detail?id=633

The attached flv file causes stack corruption when loaded into Flash. To use the PoC, load LoadMP42.swf?file=lownull.flv from a remote server.


Proof of Concept:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39466.zip