Click-jacking attack in Adobe AIR and Adobe Flash Player - CVE-2010-2215
Published: January 21, 2017
Vulnerability details
The vulnerability allows a remote attacker to perform click-jacking attacks.
The vulnerability exists due to input validation error when processing untrusted data. A remote unauthenticated attacker can create a specially crated .swf file, trick the victim into opening it and perform click-jacking attack.
Successful exploitation of this vulnerability may allow an attacker to gain access to potentially sensitive date or perform phishing attacks.
Affected software
Adobe Flash Player
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
HP Systems Insight Manager
How to mitigate CVE-2010-2215
Adobe Flash Player 10.1.82.76
AIR 2.0.3
Flash CS3 Professional and Flex 3 9.0.280