header-logo
Suggest Exploit
vendor:
Flash Player
by:
Alexander Gavrun, sinn3r, juan vazquez
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Flash Player
Affected Version From: Flash Player 11.1.102.55
Affected Version To: Flash Player 10.3.183.10
Patch Exists: YES
Related CWE: CVE-2012-0754
CPE: a:adobe:flash_player
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3, Windows Vista
2012

Adobe Flash Player MP4 ‘cprt’ Overflow

This module exploits a vulnerability found in Adobe Flash Player. By supplying a corrupt .mp4 file loaded by Flash, it is possible to gain arbitrary remote code execution under the context of the user. This vulnerability has been exploited in the wild as part of the 'Iran's Oil and Nuclear Situation.doc' e-mail attack.

Mitigation:

Adobe has released a security update to address this vulnerability. Users are advised to update to the latest version of Adobe Flash Player.
Source

Exploit-DB raw data: