Vulnerable Systems:
* Adobe Shockwave Player version 11.5.9.615 and prior
Immune Systems:
* Adobe Shockwave Player version 11.5.9.620
The vulnerability is caused by a memory corruption error in the "DIRAPI.dll" module when processing the "LCTX" chunk within a Director File, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a malicious web page.
Disclosure Timeline:
2010-05-15 - Vulnerability Discovered
2010-xx-xx - Vulnerability rediscovered by third parties
2011-02-08 - Adobe security update released