Earlier this week Adobe released a security advisory (APSA16-02) which disclosed that a critical vulnerability (CVE-2016-4117) was present in versions of Adobe Flash Player. Reports also said it was being exploited in the wild. A successful exploit could cause the targeted system to crash and potentially allow arbitrary code to run on the system, allowing an attacker to take control of it. Note that Adobe has released the patch on May 12.
We would like to dive into the detail this vulnerability to provide additional background information about this threat.
Post from: Trendlabs Security Intelligence Blog – by Trend Micro
New Flash Vulnerability CVE-2016-4117 Shares Similarities With Older Pawn Storm Exploit