Skip to main content

Adobe Flash Player Content Processing Code Execution Vulnerability

Last Update Date: 18 Apr 2011 Release Date: 13 Apr 2011 5262 Views

RISK: Extremely High Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

A vulnerability has been identified in Adobe Flash Player, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by a memory corruption error when processing malformed Flash content, which could be exploited by attackers to compromise a vulnerable system by tricking a user into visiting a specially crafted web page.

This vulnerability is exploited in the wild.


Impact

  • Remote Code Execution

System / Technologies affected

  • Adobe Flash Player version 10.2.153.1 and prior
  • Adobe Flash Player version 10.2.156.12 and prior for Android

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to Adobe Flash Player (Windows, Macintosh, Linux, and Solaris) version 10.2.159.1
  • Update to Adobe AIR (Windows, Macintosh and Linux) version 2.6.19140
  • It is expected that an update for Adobe Flash Player 10.2.156.12 and earlier versions for Android will be available no later than the week of April 25, 2011.

Vulnerability Identifier


Source


Related Link