Lucene search

K
zdiAnonymousZDI-17-486
HistoryJul 12, 2017 - 12:00 a.m.

Adobe Flash BrokerCreateFile Broker Method Information Disclosure Vulnerability

2017-07-1200:00:00
Anonymous
www.zerodayinitiative.com
15

0.002 Low

EPSS

Percentile

64.4%

This vulnerability allows remote attackers to bypass the Enhanced Protected Mode sandbox of vulnerable installations of Adobe Flash Player and disclose file contents. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the BrokerCreateFile method. An attacker can use this component to read the contents of any file that the current user has access to.