vendor:
Flash Player
by:
Unknown, hdarwin, juan vazquez
N/A
CVSS
N/A
Use After Free
Unknown
CWE
Product Name: Flash Player
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2015-0313
CPE: Unknown
Metasploit:
https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb15-04-cve-2015-0331/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-0331/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-0320/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-0322/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-0322/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-0315/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-0315/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb15-04-cve-2015-0315/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb15-04-cve-2015-0320/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb15-04-cve-2015-0322/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-0320/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-734bcd49-aae6-11e4-a0c1-c485083ca99c/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-0313/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb15-04-cve-2015-0313/
Platforms Tested: Windows
2015
Adobe Flash Player ByteArray With Workers Use After Free
This module exploits an use after free vulnerability in Adobe Flash Player. The vulnerability occurs when the ByteArray assigned to the current ApplicationDomain is freed from an ActionScript worker, who can fill the memory and notify the main thread to corrupt the new contents. This module has been tested successfully on Windows 7 SP1 (32 bits), IE 8 to IE 11 and Flash 16.0.0.296.
Mitigation:
Unknown