Adobe Shockwave Player 'DIRAPI.dll' Remote Code Execution Vulnerability
10 Apr. 2012
Summary
This allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir file that triggers an invalid read operation.
Vulnerable Systems:
* Adobe Shockwave Player 11.5.6 .606
* Adobe Shockwave Player 11.5.2 .606
* Adobe Shockwave Player 11.5.2 .602
* Adobe Shockwave Player 11.5.1 .601
* Adobe Shockwave Player 11.5 .601
* Adobe Shockwave Player 11.5 .600
* Adobe Shockwave Player 11.5 .596
Immune Systems:
* Adobe Shockwave Player 11.5.7.609
* Adobe Director 11.5.7.609
Adobe Shockwave Player is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Adobe Shockwave Player 11.5.6.606 and prior are vulnerable.
Vendor Status:
Adobe as issued an update for this vulnerablity.