Adobe Flash Player NetConnection Type Confusion

Discussion in 'News Aggregator' started by Packet Storm, 7 May 2015.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits a type confusion vulnerability in the NetConnection class on Adobe Flash Player. When using a correct memory layout this vulnerability allows to corrupt arbitrary memory. It can be used to overwrite dangerous objects, like vectors, and finally accomplish remote code execution. This Metasploit module has been tested successfully on Windows 7 SP1 (32-bit), IE 8 and IE11 with Flash 16.0.0.305.

    Continue reading...
     

Share This Page

Loading...