vendor:
Flash Player
by:
7.5
CVSS
HIGH
Use-after-free
416
CWE
Product Name: Flash Player
Affected Version From: Adobe Flash Player
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:adobe:flash_player
Platforms Tested:
Use-after-free vulnerability in MovieClip.attachBitmap
The MovieClip.attachBitmap method in Adobe Flash Player is vulnerable to a use-after-free vulnerability. When the depth parameter is an object with the valueOf method defined, the method can free the MovieClip, which is then used, leading to potential code execution or crash.
Mitigation:
Adobe Flash Player is no longer supported and has reached end-of-life. It is recommended to uninstall Flash Player and use alternative technologies.