Heap-based buffer overflow in Adobe AIR and Adobe Flash Player - CVE-2010-1297
Published: January 3, 2017 / Updated: October 5, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing .swf files. A remote attacker can create a specially crafted .swf file, trick the victim into opening it, cause heap-based buffer overflow and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability results in compromise of vulnerable system.
Note: this vulnerability is being actively exploited.
Affected software
Adobe Flash Player
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
How to mitigate CVE-2010-1297
- Flash Player 10.1.53.64
- AIR 2.0.2.12610
- Flash Professional CS5 10.1.53.64
- Flash CS4 Professional and Flex 4 10.1.53.64
- Flash CS3 Professional and Flex 3 9.0.277.0
Links to Public Exploits and PoC-codes
- Exploit #691 - Adobe Acrobat Reader and Flash Player - 'newclass' Invalid Pointer Exploit (March 18, 2020)
- Exploit #692 - Adobe Flash and Reader - Live Malware (PoC) (March 18, 2020)
- Exploit #693 - Adobe Flash Player - 'newfunction' Invalid Pointer Use (Metasploit) (2) (March 18, 2020)
- Exploit #694 - Adobe Flash Player - 'newfunction' Invalid Pointer Use (Metasploit) (1) (March 18, 2020)
- Exploit #1649 - Adobe Flash Player "newfunction" Invalid Pointer Use (March 18, 2020)
- Exploit #1707 - Adobe Flash Player "newfunction" Invalid Pointer Use (March 18, 2020)