#VU3096 Heap-based buffer overflow in Adobe Flash Player and Adobe AIR - CVE-2010-2167
Published: January 3, 2017
Adobe Flash Player
Adobe AIR
Adobe
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to multiple boundary errors when processing .swf files. A remote attacker can create a specially crafted .swf file, trick the victim into opening it, cause heap-based buffer overflow and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability results in compromise of vulnerable system.
Remediation
- Flash Player 10.1.53.64
- AIR 2.0.2.12610
- Flash Professional CS5 10.1.53.64
- Flash CS4 Professional and Flex 4 10.1.53.64
- Flash CS3 Professional and Flex 3 9.0.277.0