An object confusion vulnerability exists within certain versions of Adobe Flash Player. This issue can cause a memory corruption to occur. By carefully triggering this vulnerability, an attacker can execute code within the context of the currently logged on user.
- Adobe Flash Player 184.108.40.206 and earlier for Windows, Macintosh and Linux
- Adobe Flash Player 220.127.116.11 and earlier for Android 4.x
- Adobe Flash Player 18.104.22.168 and earlier for Android 3.x and 2.x
Remote Code Execution
Remote Code Execution Exploitation of this vulnerability is possible through the use of methods like drive-by attacks. Remote attackers who successfully exploit this vulnerability will be able to execute code on the vulnerable system with the same rights as the currently logged on user.
BeyondTrust Prevention and Detection:
Apply the patch; no other reasonable mitigation currently exists.