Korean
<< Back
VID 50081
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description The remote Windows host contains a version of Adobe's Shockwave Player that is earlier than 12.2.0.162. It is, therefore, affected by a memory corruption issue due to improper validation of user-supplied input. An unauthenticated, remote attacker can exploit this to execute arbitrary code.

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
https://helpx.adobe.com/security/products/shockwave/apsb15-26.html

* Platforms Affected:
Shockwave Player versions prior to 12.2.0.162
Microsoft Windows Any version
Recommendation Upgrade to the latest version Shockwave Player (12.2.0.162 or later), available from the Adobe Web site at http://get.adobe.com/shockwave/
Related URL CVE-2015-7649 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)