6.4
CVSSv2

CVE-2015-3082

Published: 13/05/2015 Updated: 17/09/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Adobe Flash Player prior to 13.0.0.289 and 14.x up to and including 17.x prior to 17.0.0.188 on Windows and OS X and prior to 11.2.202.460 on Linux, Adobe AIR prior to 17.0.0.172, Adobe AIR SDK prior to 17.0.0.172, and Adobe AIR SDK & Compiler prior to 17.0.0.172 allow remote malicious users to bypass intended restrictions on filesystem write operations via unspecified vectors, a different vulnerability than CVE-2015-3083 and CVE-2015-3085.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe air

adobe air sdk

adobe air sdk \\& compiler

adobe flash_player 14.0.0.145

adobe flash_player 14.0.0.176

adobe flash_player 16.0.0.235

adobe flash_player 16.0.0.257

adobe flash_player 14.0.0.179

adobe flash_player 15.0.0.152

adobe flash_player 16.0.0.287

adobe flash_player 16.0.0.296

adobe flash_player

adobe flash_player 14.0.0.125

adobe flash_player 15.0.0.223

adobe flash_player 15.0.0.239

adobe flash_player 15.0.0.246

adobe flash_player 15.0.0.167

adobe flash_player 15.0.0.189

adobe flash_player 17.0.0.134

adobe flash_player 17.0.0.169

Vendor Advisories

Adobe Flash Player before 1300289 and 14x through 17x before 1700188 on Windows and OS X and before 112202460 on Linux, Adobe AIR before 1700172, Adobe AIR SDK before 1700172, and Adobe AIR SDK & Compiler before 1700172 allow remote attackers to bypass intended restrictions on filesystem write operations via unspecified vect ...

Exploits

Source: codegooglecom/p/google-security-research/issues/detail?id=278&can=1&q=label%3AProduct-Flash%20modified-after%3A2015%2F8%2F17&sort=id FlashBroker - Junction Check Bypass With Forward Slash IE PM Sandbox Escape 1 Windows 81 Internet Explorer Protected Mode Bypass in FlashBroker FlashBroker is vulnerable to NTFS junc ...