CVE-2015-0336
EXPLOITEDAdobe Flash Player NetConnection Type Confusion
Title source: metasploitExploitation Summary
CVE-2015-0336 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 2 public exploits from researchers including Metasploit, Natalie Silvanovich, Unknown, juan vazquez, including a Metasploit module exploits/multi/browser/adobe_flash_net_connection_confusion.
AI-analyzed exploit summary This Metasploit module exploits a type confusion vulnerability in Adobe Flash Player's NetConnection class (CVE-2015-0336) to achieve remote code execution. It uses a crafted SWF file and PowerShell payload to exploit vulnerable Flash versions (16.0.0.305 and earlier) on Windows 7 with Internet Explorer.
Description
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0334.
Exploits (2)
This Metasploit module exploits a type confusion vulnerability in Adobe Flash Player's NetConnection class (CVE-2015-0336) to achieve remote code execution. It uses a crafted SWF file and PowerShell payload to exploit vulnerable Flash versions (16.0.0.305 and earlier) on Windows 7 with Internet Explorer.
This Metasploit module exploits a type confusion vulnerability in Adobe Flash Player's NetConnection class (CVE-2015-0336) to achieve remote code execution. It leverages memory corruption to overwrite objects and execute arbitrary payloads on vulnerable systems.