4.3
CVSSv2

CVE-2015-3081

Published: 13/05/2015 Updated: 17/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Race condition in Adobe Flash Player prior to 13.0.0.289 and 14.x up to and including 17.x prior to 17.0.0.188 on Windows and OS X and prior to 11.2.202.460 on Linux, Adobe AIR prior to 17.0.0.172, Adobe AIR SDK prior to 17.0.0.172, and Adobe AIR SDK & Compiler prior to 17.0.0.172 allows malicious users to bypass the Internet Explorer Protected Mode protection mechanism via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash_player

adobe air sdk \\& compiler

adobe air

adobe air sdk

adobe flash_player 14.0.0.125

adobe flash_player 15.0.0.223

adobe flash_player 15.0.0.239

adobe flash_player 17.0.0.169

adobe flash_player 14.0.0.145

adobe flash_player 14.0.0.176

adobe flash_player 15.0.0.246

adobe flash_player 16.0.0.235

adobe flash_player 15.0.0.167

adobe flash_player 15.0.0.189

adobe flash_player 16.0.0.296

adobe flash_player 17.0.0.134

adobe flash_player 14.0.0.179

adobe flash_player 15.0.0.152

adobe flash_player 16.0.0.257

adobe flash_player 16.0.0.287

Exploits

Source: codegooglecom/p/google-security-research/issues/detail?id=280&can=1&q=label%3AProduct-Flash%20modified-after%3A2015%2F8%2F17&sort=id FlashBroker - BrokerMoveFileEx TOCTOU IE PM Sandbox Escape 1 Windows 81 Internet Explorer Protected Mode Bypass in FlashBroker FlashBroker is vulnerable to NTFS junction attack to wr ...