Lucene search

K
hackeroneHhj4ckH1:119655
HistoryMar 01, 2016 - 8:03 a.m.

Internet Bug Bounty: Adobe Flash Player ASnative(900,1).call(TextField) Use-After-Free Vulnerability

2016-03-0108:03:36
hhj4ck
hackerone.com
21

0.019 Low

EPSS

Percentile

88.4%

I. Summary
Adobe Flash Player is prone to a vulnerability which leads to Use-After-Free.

II. Description
If the ASnative(900,1) is invoked with TextField instance and getter properties associated with swfRoot where the getter method includes a call to removeTextField(), the TextField instance is used after it is freed.

The zip attachment contains the crash.swf and its source code.
Latest version of Adobe Flash Player 20.0.0.267 has been tested under Windows 7.

III. Impact
Use-After-Free

IV. Credit
Wen Guanxing from Venustech ADLAB is credited for this vulnerability.

It has been assigned by Adobe as CVE-2016-0983
https://helpx.adobe.com/security/products/flash-player/apsb16-04.html