Adobe Flash Player Content Processing Code Execution Vulnerability
RISK: Extremely High Risk
TYPE: Clients - Audio & Video
A vulnerability has been identified in Adobe Flash Player, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by a memory corruption error when processing malformed Flash content, which could be exploited by attackers to compromise a vulnerable system by tricking a user into visiting a specially crafted web page.
This vulnerability is exploited in the wild.
Impact
- Remote Code Execution
System / Technologies affected
- Adobe Flash Player version 10.2.153.1 and prior
- Adobe Flash Player version 10.2.156.12 and prior for Android
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to Adobe Flash Player (Windows, Macintosh, Linux, and Solaris) version 10.2.159.1
- Update to Adobe AIR (Windows, Macintosh and Linux) version 2.6.19140
- It is expected that an update for Adobe Flash Player 10.2.156.12 and earlier versions for Android will be available no later than the week of April 25, 2011.
Vulnerability Identifier
Source
Related Link
Share with