Adobe Flash Player 'schannel.dll' DLL Loading Arbitrary Code Execution Vulnerability
BID:42807
Info
Adobe Flash Player 'schannel.dll' DLL Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 42807 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 27 2010 12:00AM |
| Updated: | Aug 27 2010 12:00AM |
| Credit: | Securitylab.ir (Kamran Safaei Tabrizi) |
| Vulnerable: |
Adobe Flash Player 9.0.262 Adobe Flash Player 9.0.246 0 Adobe Flash Player 9.0.152 .0 Adobe Flash Player 9.0.151 .0 Adobe Flash Player 9.0.124 .0 Adobe Flash Player 9.0.48.0 Adobe Flash Player 9.0.47.0 Adobe Flash Player 9.0.45.0 Adobe Flash Player 9.0.31.0 Adobe Flash Player 9.0.280 Adobe Flash Player 9.0.28.0 Adobe Flash Player 9.0.277.0 Adobe Flash Player 9.0.260.0 Adobe Flash Player 9.0.246.0 Adobe Flash Player 9.0.159.0 Adobe Flash Player 9.0.115.0 Adobe Flash Player 9 |
| Not Vulnerable: | |
Discussion
Adobe Flash Player 'schannel.dll' DLL Loading Arbitrary Code Execution Vulnerability
Adobe Flash Player is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Adobe Flash Player is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Exploit / POC
Adobe Flash Player 'schannel.dll' DLL Loading Arbitrary Code Execution Vulnerability
Attackers can exploit this issue by tricking a victim into opening a file on a WebDAV or SMB share.
Attackers can exploit this issue by tricking a victim into opening a file on a WebDAV or SMB share.
Solution / Fix
Adobe Flash Player 'schannel.dll' DLL Loading Arbitrary Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].