vendor:
Flash Player
by:
Google Security Research
9.3
CVSS
HIGH
Use-After-Free
416
CWE
Product Name: Flash Player
Affected Version From: 17.0.0.188
Affected Version To: 17.0.0.188
Patch Exists: YES
Related CWE: N/A
CPE: a:adobe:flash_player:17.0.0.188
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Chrome, Linux, Chrome
2015
Use-After-Free Vulnerability in Adobe Flash Player 17.0.0.188
The crash was observed in Flash Player 17.0.0.188 on Windows due to a use-after-free related to loading a sub-resource from a URL. The crash appears to occur when a jmp instruction is executed. The test case reproduces on Windows 7 using IE11, but does not appear to immediately reproduce on Windows+Chrome or Linux+Chrome.
Mitigation:
Update to the latest version of Adobe Flash Player.