Click-jacking attack in Adobe Flash Player and Adobe AIR - CVE-2010-2215
Published: January 21, 2017
Adobe Flash Player
Adobe AIR
Detailed vulnerability description
The vulnerability allows a remote attacker to perform click-jacking attacks.
The vulnerability exists due to input validation error when processing untrusted data. A remote unauthenticated attacker can create a specially crated .swf file, trick the victim into opening it and perform click-jacking attack.
Successful exploitation of this vulnerability may allow an attacker to gain access to potentially sensitive date or perform phishing attacks.
How to mitigate CVE-2010-2215
Adobe Flash Player 10.1.82.76
AIR 2.0.3
Flash CS3 Professional and Flex 3 9.0.280