vendor:
Flash Player
by:
Natalie Silvanovich, Unknown, juan vazquez
9.3
CVSS
HIGH
Type Confusion
843
CWE
Product Name: Flash Player
Affected Version From: 16.0.0.305
Affected Version To: 16.0.0.305
Patch Exists: YES
Related CWE: CVE-2015-0336
CPE: a:adobe:flash_player:16.0.0.305
Metasploit:
https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-0336/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-0334/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2015-0336/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-0336/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2015-0334/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-0334/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-0697/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb15-05-cve-2015-0334/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb15-05-cve-2015-0336/
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=81908, https://www.infosecmatter.com/nessus-plugin-library/?id=83698, https://www.infosecmatter.com/nessus-plugin-library/?id=81877, https://www.infosecmatter.com/nessus-plugin-library/?id=81732, https://www.infosecmatter.com/nessus-plugin-library/?id=84159, https://www.infosecmatter.com/nessus-plugin-library/?id=81819, https://www.infosecmatter.com/nessus-plugin-library/?id=81867, https://www.infosecmatter.com/nessus-plugin-library/?id=82008, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/browser/adobe_flash_net_connection_confusion, https://www.infosecmatter.com/list-of-metasploit-linux-exploits-detailed-spreadsheet/
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 SP1 (32-bit), IE 8 and IE11
2015
Adobe Flash Player NetConnection Type Confusion
This module exploits a type confusion vulnerability in the NetConnection class on Adobe Flash Player. When using a correct memory layout this vulnerability allows to corrupt arbitrary memory. It can be used to overwrite dangerous objects, like vectors, and finally accomplish remote code execution. This module has been tested successfully on Windows 7 SP1 (32-bit), IE 8 and IE11 with Flash 16.0.0.305.
Mitigation:
Adobe has released a security update to address this vulnerability. Users are advised to update to the latest version of Adobe Flash Player.