vendor:
Flash Player
by:
Unknown
7,5
CVSS
HIGH
Unspecified Vulnerability
119
CWE
Product Name: Flash Player
Affected Version From: Adobe Flash Player 10.0.45.2 and earlier versions
Affected Version To: Adobe Flash Player 10.1.53.64 and earlier versions
Patch Exists: YES
Related CWE: CVE-2010-1297
CPE: a:adobe:flash_player
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0503/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0464/, https://www.rapid7.com/db/vulnerabilities/hpsim-cve-2010-1297/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2010-1297/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2010-1297/, https://www.rapid7.com/db/vulnerabilities/adobe-reader-apsb10-15-CVE-2010-1297/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2010-1297/, https://www.rapid7.com/db/vulnerabilities/apple-osx-flashplayerplugin-cve-2010-1297/, https://www.rapid7.com/db/vulnerabilities/adobe-unspec-bof-cve-2010-1297/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2010
Unspecified Vulnerability in Adobe Flash Player
This exploit is related to an unspecified vulnerability in Adobe Flash Player. The vulnerability is exploited by a malicious SWF file embedded in a web page. The malicious SWF file is used to create a heap spray which is used to overwrite the return address of a function and execute arbitrary code. The vulnerability is triggered when the user visits a malicious web page.
Mitigation:
Adobe has released a security update to address this vulnerability. Users are advised to update their Adobe Flash Player to the latest version.