PT-2010-5208 · Adobe · Flash Player
Simon Raner
·
Published
2010-10-19
·
Updated
2018-10-10
·
CVE-2010-3976
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Flash Player versions prior to 9.0.289.0
Adobe Flash Player versions 10.x prior to 10.1.102.64
Description
The issue allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll. This occurs when the malicious dwmapi.dll is located in the same folder as a file that is processed by Flash Player.
Recommendations
For Adobe Flash Player versions prior to 9.0.289.0, update to version 9.0.289.0 or later.
For Adobe Flash Player versions 10.x prior to 10.1.102.64, update to version 10.1.102.64 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flash Player