Adobe Flash Player CVE-2012-1535 Remote Code Execution Vulnerability
BID:55009
Info
Adobe Flash Player CVE-2012-1535 Remote Code Execution Vulnerability
| Bugtraq ID: | 55009 |
| Class: | Unknown |
| CVE: |
CVE-2012-1535 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 14 2012 12:00AM |
| Updated: | Mar 19 2015 09:10AM |
| Credit: | Alexander Gavrun through iDefense's Vulnerability Contributor Program. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Desktop 11 SP2 SuSE SUSE Linux Enterprise Desktop 11 SP1 SuSE openSUSE 12.1 SuSE openSUSE 11.4 Research In Motion Blackberry PlayBook Tablet Software 2.0.0.7971 Research In Motion Blackberry PlayBook Tablet Software 1.0.8.6067 Research In Motion Blackberry PlayBook Tablet Software 1.0.8.4985 Research In Motion Blackberry PlayBook Tablet Software 1.0.7.3312 Research In Motion Blackberry PlayBook Tablet Software 1.0.7.2942 Research In Motion Blackberry PlayBook Tablet Software 1.0.6 Research In Motion Blackberry PlayBook Tablet Software 1.0.5.2342 Research In Motion Blackberry PlayBook Tablet Software 1.0.5.2304 Red Hat Enterprise Linux Workstation Supplementary 6 Red Hat Enterprise Linux Supplementary 5 server Red Hat Enterprise Linux Server Supplementary 6 Red Hat Enterprise Linux Desktop Supplementary 6 Red Hat Enterprise Linux Desktop Supplementary 5 client openSUSE openSUSE 12.2 HP Systems Insight Manager 7.0 HP Systems Insight Manager 6.3 HP Systems Insight Manager 6.2 HP Systems Insight Manager 6.1 HP Systems Insight Manager 6.0.0.96 HP Systems Insight Manager 6.0 Google Chrome 17.0.963 79 Google Chrome 17.0.963 65 Google Chrome 16.0.912 75 Google Chrome 2.0.172 .43 Google Chrome 2.0.172 .37 Google Chrome 2.0.172 .33 Google Chrome 2.0.172 .31 Google Chrome 2.0.172 .30 Google Chrome 2.0.172.8 Google Chrome 2.0.172.38 Google Chrome 2.0.172.28 Google Chrome 2.0.172.27 Google Chrome 2.0.172.2 Google Chrome 2.0.172 Google Chrome 2.0.170.0 Google Chrome 2.0.169.1 Google Chrome 2.0.169.0 Google Chrome 2.0.159.0 Google Chrome 2.0.158.0 Google Chrome 2.0.157.2 Google Chrome 2.0.157.0 Google Chrome 2.0.156.1 Google Chrome 19.0.1084.52 Google Chrome 19 Google Chrome 18.0.1025.168 Google Chrome 18.0.1025.162 Google Chrome 18.0.1025.151 Google Chrome 18.0.1025.142 Google Chrome 17.0.963.83 Google Chrome 17.0.963.78 Google Chrome 17.0.963.60 Google Chrome 17.0.963.56 Google Chrome 17.0.963.46 Google Chrome 16.0.912.77 Google Chrome 16.0.912.75 Google Chrome 16.0.912.63 Google Chrome 16 Gentoo Linux Adobe Flash Player 11.2.202.235 Adobe Flash Player 11.2.202.233 Adobe Flash Player 11.2.202.229 Adobe Flash Player 11.2.202.228 Adobe Flash Player 11.2.202.223 Adobe Flash Player 11.1.115.8 Adobe Flash Player 11.1.115.7 Adobe Flash Player 11.1.115.6 Adobe Flash Player 11.1.112.61 Adobe Flash Player 11.1.111.9 Adobe Flash Player 11.1.111.8 Adobe Flash Player 11.1.111.7 Adobe Flash Player 11.1.111.6 Adobe Flash Player 11.1.111.5 Adobe Flash Player 11.1.102.63 Adobe Flash Player 11.1.102.62 Adobe Flash Player 11.1.102.55 Adobe Flash Player 11.1.102.228 Adobe Flash Player 11.0.1.152 |
| Not Vulnerable: | |
Discussion
Adobe Flash Player CVE-2012-1535 Remote Code Execution Vulnerability
Adobe Flash Player is prone to an unspecified remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Adobe Flash Player 11.3.300.270 and earlier versions are vulnerable.
Adobe Flash Player is prone to an unspecified remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Adobe Flash Player 11.3.300.270 and earlier versions are vulnerable.
Exploit / POC
Adobe Flash Player CVE-2012-1535 Remote Code Execution Vulnerability
Reports indicate that the vulnerability is being exploited in the wild in limited, targeted attacks distributed through a malicious Word document. The exploit targets the ActiveX version of Flash Player for Internet Explorer on Windows.
The following exploit is available:
Reports indicate that the vulnerability is being exploited in the wild in limited, targeted attacks distributed through a malicious Word document. The exploit targets the ActiveX version of Flash Player for Internet Explorer on Windows.
The following exploit is available:
Solution / Fix
Adobe Flash Player CVE-2012-1535 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Adobe Flash Player CVE-2012-1535 Remote Code Execution Vulnerability
References:
References:
- Adobe Flash Homepage (Adobe)
- openSUSE-SU-2013:0362-1: critical: flash-player to 11.2.202.238 (OpenSUSE)
- Stable Channel Update: 21.0.1180.79 (Google)
- APSB12-18: Security update available for Adobe Flash Player (Adobe)
- BSRT-2013-001 Vulnerabilities in Adobe Flash Player version included with the Bl (Research In Motion)
- HP Systems Insight Manager (SIM) Running on Linux and Windows, Remote Execution (HP)
- Microsoft Security Advisory (2755801) Update for Vulnerabilities in Adobe Flash (Microsoft)