#VU5767 Security bypass in Adobe products - CVE-2016-1006
Published: February 13, 2017
Vulnerability identifier: #VU5767
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2016-1006
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Adobe Flash Player
Adobe Flash Player Extended Support Release
Adobe Flash Player for Linux
Adobe AIR
Adobe Flash Player
Adobe Flash Player Extended Support Release
Adobe Flash Player for Linux
Adobe AIR
Software vendor:
Adobe
Adobe
Description
The vulnerabiity allows a remote attacker to bypass security restrictions on the target system.
The weakness exists due to failure to use Address Space Layout Randomization (ASLR). A remote attacker can create a specially crafted Web site, trick the victim into visiting it, conduct a JIT spraying attack and bypass memory layout randomization mitigations.
Successful exploitation of this vulnerability results in security bypass on the vulnerable system.
The weakness exists due to failure to use Address Space Layout Randomization (ASLR). A remote attacker can create a specially crafted Web site, trick the victim into visiting it, conduct a JIT spraying attack and bypass memory layout randomization mitigations.
Successful exploitation of this vulnerability results in security bypass on the vulnerable system.
Remediation
Install update from vendor's website.