vendor:
Flash Player
by:
Google Security Research
7.8
CVSS
HIGH
Out-of-bounds write
787
CWE
Product Name: Flash Player
Affected Version From: Adobe Flash Player 15.0.0.223 and earlier
Affected Version To: Adobe Flash Player 18.0.0.203 and earlier
Patch Exists: YES
Related CWE: CVE-2015-3006
CPE: a:adobe:flash_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2015
Out-of-bounds write in Flash Player
An out-of-bounds write vulnerability exists in Adobe Flash Player. The vulnerability is caused due to an indexing error when the rdi “base” address is in bounds but add on 2*rdx and the address is not in bounds. This can be exploited to corrupt memory via a specially crafted SWF file.
Mitigation:
Users should update to the latest version of Adobe Flash Player.