Executive brief
A use-after-free vulnerability exists in the ByteArray class within the ActionScript 3 implementation of Adobe Flash Player. Remote attackers can exploit this by using crafted Flash content that overrides the valueOf function, leading to arbitrary code execution or denial of service.
Affected products
- Adobe Flash Player 13.x through 13.0.0.296 (Windows/OS X)
- Adobe Flash Player 14.x through 18.0.0.194 (Windows/OS X)
- Adobe Flash Player 11.x through 11.2.202.468 (Linux)
Timeline
- 2015-07: exploited: Exploited in the wild as part of the Hacking Team leak.
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.