CVE-2016-4232
HIGHAdobe Flash Player <18.0.0.366,19.x-22.x - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-4232. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates an information leak in Adobe Flash's Transform.colorTransform getter by overwriting the ColorTransform constructor with a getter that frees the MovieClip, leading to the exposure of unallocated memory values.
Description
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to obtain sensitive information from process memory via unspecified vectors.
Exploits (1)
This exploit demonstrates an information leak in Adobe Flash's Transform.colorTransform getter by overwriting the ColorTransform constructor with a getter that frees the MovieClip, leading to the exposure of unallocated memory values.
References (9)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N