Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
The product does not correctly convert an object, resource, or structure from one type to a different type.
Link | Tags |
---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-141 | patch vendor advisory |
https://helpx.adobe.com/security/products/flash-player/apsb16-37.html | patch vendor advisory |
http://rhn.redhat.com/errata/RHSA-2016-2676.html | third party advisory vendor advisory |
http://www.securityfocus.com/bid/94151 | vdb entry third party advisory |
http://www.securitytracker.com/id/1037240 | vdb entry third party advisory |
http://www.zerodayinitiative.com/advisories/ZDI-16-600 | vdb entry third party advisory |
https://security.gentoo.org/glsa/201611-18 | third party advisory vendor advisory |