vendor:
Flash Player
by:
Nicolas Joly, Unknown, juan vazquez
9.3
CVSS
HIGH
Uninitialized Memory
125
CWE
Product Name: Flash Player
Affected Version From: 15.0.0.189
Affected Version To: 15.0.0.189
Patch Exists: YES
Related CWE: CVE-2014-8440
CPE: a:adobe:flash_player:15.0.0.189
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2014-1852/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2014-0576/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2014-0581/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-0576/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-0581/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2014-8440/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2014-8441/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-8440/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-8441/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2014-0576/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2014-0581/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2014-8440/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2014-8441/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb14-24-cve-2014-0576/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb14-24-cve-2014-8440/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb14-24-cve-2014-8441/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb14-24-cve-2014-0581/
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=79228, https://www.infosecmatter.com/nessus-plugin-library/?id=79308, https://www.infosecmatter.com/nessus-plugin-library/?id=79141, https://www.infosecmatter.com/nessus-plugin-library/?id=79142, https://www.infosecmatter.com/nessus-plugin-library/?id=79324, https://www.infosecmatter.com/nessus-plugin-library/?id=79143, https://www.infosecmatter.com/nessus-plugin-library/?id=79139, https://www.infosecmatter.com/nessus-plugin-library/?id=79145, https://www.infosecmatter.com/nessus-plugin-library/?id=79404, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/browser/adobe_flash_uncompress_zlib_uninitialized
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 SP1 (32-bit), IE 8 and IE11
2014
Adobe Flash Player UncompressViaZlibVariant Uninitialized Memory
This module exploits an unintialized memory vulnerability in Adobe Flash Player. The vulnerability occurs in the ByteArray::UncompressViaZlibVariant method, which fails to initialize allocated memory. When using a correct memory layout this vulnerability leads to a ByteArray object corruption, which can be abused to access and corrupt memory. This module has been tested successfully on Windows 7 SP1 (32-bit), IE 8 and IE11 with Flash 15.0.0.189.
Mitigation:
Adobe has released a security update to address this vulnerability. Users are advised to update to the latest version of Adobe Flash Player.