PT-2015-2833 · Adobe+3 · Integrated Runtime+7
Published
2015-12-09
·
Updated
2023-05-08
·
CVE-2015-8413
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Integrated Runtime versions (affected versions not specified)
Adobe Flash Player versions (affected versions not specified)
Adobe AIR versions (affected versions not specified)
Adobe AIR SDK versions (affected versions not specified)
Adobe AIR SDK & Compiler versions (affected versions not specified)
Description
The issue is related to the use of memory after it has been freed, which can allow a remote attacker to execute arbitrary code. This can be exploited by malicious actors to gain unauthorized access and control.
Recommendations
For Adobe Integrated Runtime, update to a version that addresses the use-after-free issue.
For Adobe Flash Player, consider disabling the vulnerable component until a patch is available.
For Adobe AIR, restrict access to vulnerable modules to minimize the risk of exploitation.
For Adobe AIR SDK, avoid using vulnerable parameters in affected API endpoints until the issue is resolved.
For Adobe AIR SDK & Compiler, as a temporary workaround, consider disabling vulnerable functions until a patch is available.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Air
Air Sdk
Air Sdk & Compiler
Flash Player
Integrated Runtime
Red Hat
Suse