CVE-2015-0359
EXPLOITEDAdobe Flash Player domainMemory ByteArray Use After Free
Title source: metasploitExploitation Summary
CVE-2015-0359 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 2 public exploits from researchers including Metasploit, bilou, Unknown, hdarwin, juan vazquez, including a Metasploit module exploits/windows/browser/adobe_flash_domain_memory_uaf.
AI-analyzed exploit summary This Metasploit module exploits a use-after-free vulnerability in Adobe Flash Player (CVE-2015-0359) by manipulating the ByteArray assigned to the current ApplicationDomain. It delivers a malicious SWF file to trigger the vulnerability and execute arbitrary code via a PowerShell payload.
Description
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0346.
Exploits (2)
This Metasploit module exploits a use-after-free vulnerability in Adobe Flash Player (CVE-2015-0359) by manipulating the ByteArray assigned to the current ApplicationDomain. It delivers a malicious SWF file to trigger the vulnerability and execute arbitrary code via a PowerShell payload.
This Metasploit module exploits a use-after-free vulnerability in Adobe Flash Player (CVE-2015-0359) by manipulating the domainMemory ByteArray pointer. It delivers a malicious SWF file via a browser exploit server to achieve remote code execution on vulnerable systems.