vendor:
Flash Player
by:
Francis Provencher of COSIG
8,8
CVSS
HIGH
Remote Code Execution
119
CWE
Product Name: Flash Player
Affected Version From: 22.0.0.192
Affected Version To: Earlier
Patch Exists: YES
Related CWE: CVE-2016-4176
CPE: a:adobe:flash_player
Metasploit:
https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2016-4176/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2016-4177/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2016-4176/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2016-4177/, https://www.rapid7.com/db/vulnerabilities/flash_player-cve-2016-4176/, https://www.rapid7.com/db/vulnerabilities/flash_player-cve-2016-4177/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, OSX
2016
Adobe Flash Player Exploit
The vulnerability allows a remote attacker to execute malicious code or access to a part of the dynamically allocated memory using a user interaction visiting a Web page or open a specially crafted SWF file, which contains ‘TAG’ invalid data.
Mitigation:
Adobe released a patch (APSB16-25) to address this vulnerability.