Lucene search

K
hackeroneHhj4ckH1:145266
HistoryJun 17, 2016 - 12:54 a.m.

Internet Bug Bounty: Adobe Flash Player ShimContentFactory.retrieveResolvers Memory Corruption Vulnerability

2016-06-1700:54:50
hhj4ck
hackerone.com
25

EPSS

0.01

Percentile

83.3%

I. Summary
Adobe Flash Player is prone to a vulnerability which leads to memory corruption because of improper validation of ShimContentFactory.retrieveResolvers().

II. Description
Normally, retrieveResolvers() should validates its parameter and returns error in AS3 level if anything goes wrong.
If retrieveResolvers() function is invoked directly with invalid parameter, some inner class instance will be absent, which will cause a memory crash.

III. Impact
Memory Corruption

IV. Affected
Adobe Flash Player 21.0.0.242.

V. Credit
Wen Guanxing from Pangu LAB is credited for this vulnerability.

It has been assigned by Adobe as CVE-2016-4151.
https://helpx.adobe.com/security/products/flash-player/apsb16-18.html