BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to the Zeroday Tracker: Your Vulnerability Watchlist

Get critical updates on the latest zeroday threats, including impact, mitigation and protection information - only from BeyondTrust.

Vulnerability in Adobe Flash Player Could Allow Remote Code Execution

Disclosed May 4, 2012    Fully Patched

Vulnerability Description:

An object confusion vulnerability exists within certain versions of Adobe Flash Player. This issue can cause a memory corruption to occur. By carefully triggering this vulnerability, an attacker can execute code within the context of the currently logged on user.

Vendors:

Adobe

Vulnerable Software/Devices:

  • Adobe Flash Player 11.2.202.233 and earlier for Windows, Macintosh and Linux
  • Adobe Flash Player 11.1.115.7 and earlier for Android 4.x
  • Adobe Flash Player 11.1.111.8 and earlier for Android 3.x and 2.x

Vulnerability Severity:

High

Exploit Availability:

N/A

Exploit Impact:

Remote Code Execution
Remote Code Execution Exploitation of this vulnerability is possible through the use of methods like drive-by attacks. Remote attackers who successfully exploit this vulnerability will be able to execute code on the vulnerable system with the same rights as the currently logged on user.

BeyondTrust Prevention and Detection:

 

Mitigation:

Apply the patch; no other reasonable mitigation currently exists.

Links:

CVE(s):

None

Leave a Reply