Adobe Flash Player And AIR APSB15-32 Allows Unauthorized Disclosure Of Information Execute Arbitrary Code Vulnerabilities
16 Mar. 2016
Summary
Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to execute arbitrary code or cause a denial of service
Credit:
The information has been provided by Anonymous working with HPE's Zero Day Initiative, bilou working with HPE's Zero Day Initiative, Furugawa Nagisa working with HPE's Zero Day Initiative, LMX of Qihoo 360, Natalie Silvanovich of Google Project Zero, Nicolas Joly of Microsoft Security and Yuk.
Vulnerable Systems:
* Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204
Immune Systems:
* Adobe Flash Player after 18.0.0.268 and 19.x and 20.x after 20.0.0.228 on Windows and OS X and after 11.2.202.554 on Linux, Adobe AIR after 20.0.0.204, Adobe AIR SDK after 20.0.0.204, and Adobe AIR SDK & Compiler after 20.0.0.204
Adobe Flash Player and AIR are prone to multiple memory-corruption vulnerabilities. An attacker can exploit these issues to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.