CVE-2014-8440
Adobe Flash Player <13.0.0.252/14.x-15.x<15.0.0.223 - RCE/DoS via Memory Corruption
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2014-8440.
PoCs published by Metasploit, Nicolas Joly, Unknown, juan vazquez, including Metasploit module exploits/windows/browser/adobe_flash_uncompress_zlib_uninitialized.
AI-analyzed exploit summary This Metasploit module exploits CVE-2014-8440, an uninitialized memory vulnerability in Adobe Flash Player's ByteArray::UncompressViaZlibVariant method. It delivers a malicious SWF file to trigger memory corruption and execute a PowerShell payload for remote code execution.
Description
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0576, CVE-2014-0581, and CVE-2014-8441.
Exploits (2)
This Metasploit module exploits CVE-2014-8440, an uninitialized memory vulnerability in Adobe Flash Player's ByteArray::UncompressViaZlibVariant method. It delivers a malicious SWF file to trigger memory corruption and execute a PowerShell payload for remote code execution.
This Metasploit module exploits an uninitialized memory vulnerability in Adobe Flash Player's ByteArray::UncompressViaZlibVariant method, leading to memory corruption and arbitrary code execution. It delivers a malicious SWF file via a crafted HTML page to trigger the vulnerability.