vendor:
Flash Player
by:
Natalie Silvanovich
9.3
CVSS
HIGH
Use-after-Free
416
CWE
Product Name: Flash Player
Affected Version From: Adobe Flash Player 18.0.0.194 and earlier
Affected Version To: Adobe Flash Player 18.0.0.203 and earlier
Patch Exists: YES
Related CWE: CVE-2015-7645
CPE: o:adobe:flash_player:18.0.0.194
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-2024/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-1913/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-7645/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-7645/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb15-27-cve-2015-7645/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2015
Use-after-Free in TextField gridFitType setter
A use-after-free vulnerability exists in the TextField gridFitType setter in Adobe Flash Player. The vulnerability is caused by a race condition when the TextField object is removed while the gridFitType setter is being called. An attacker can exploit this vulnerability to execute arbitrary code in the context of the current user.
Mitigation:
Upgrade to the latest version of Adobe Flash Player.