#VU5746 Untrusted Search Path in Adobe products - CVE-2016-1014
Published: February 13, 2017 / Updated: March 7, 2017
Adobe Flash Player
Adobe Flash Player Extended Support Release
Adobe Flash Player for Linux
Adobe AIR
Adobe
Description
The weakness exists due to an error in the directory search path used to find resources when handling .swf files. A remote attacker can create a specially crafted .swf file, place it with malicious .dll on remote SMB or WebDav share, trick the victim into opening Flash file it and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability results in arbitrary code execution.