A memory corruption flaw exists in Adobe Flash Player. The program fails to sanitize user-supplied input when an error occurs during the decoding of an MP4 stream, which will result in a memory corruption. This may allow a remote attacker to execute arbitrary code.
Classification
Location:
Local / Remote,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Patch / RCS,
Upgrade
Exploit:
Exploit Public,
Exploit Private
Disclosure:
Vendor Verified,
Coordinated Disclosure
Solution
Upgrade to version 11.1.102.62 or higher (11.1.115.6 for Android), as it has been reported to fix this vulnerability. In addition, Adobe has released a patch for some older versions.