Korean
<< Back
VID 50069
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description According to its version, the Adobe Flash Player installed on the remote Windows host is equal or prior to 16.0.0.287. It is, therefore, affected by the following vulnerabilities :

- A use-after-free error exists that allows an attacker to crash the application or execute arbitrary code. (CVE-2015-0311)

- A double-free error exists that allows an attacker to crash the application or possibly execute arbitrary code. (CVE-2015-0312)

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://helpx.adobe.com/security/products/flash-player/apsa15-01.html
http://helpx.adobe.com/security/products/flash-player/apsb15-03.html
https://helpx.adobe.com/flash-player/kb/archived-flash-player-versions.html
http://www.adobe.com/products/flashplayer/distribution3.html

* Platforms Affected:
Adobe Flash Player equal or prior to 16.0.0.287
Apple Mac OS X Any version
Linux Any version
Microsoft Windows Any version
Recommendation Upgrade to the latest version of Adobe Flash Player (16.0.0.287 later), available from the Adobe Web site at http://get.adobe.com/flashplayer/
Related URL CVE-2015-0311,CVE-2015-0312 (CVE)
Related URL 72283,72343 (SecurityFocus)
Related URL (ISS)