HTTP: Adobe Flash Player ActiveX Null Dereference

This signature detects attempts to exploit a known vulnerability in Adobe Flash Play ActiveX. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX calls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

Adobe Flash Player is prone to multiple security vulnerabilities. An attacker can exploit these issues to execute arbitrary code in the context of the user running the affected application or disclose sensitive information. Failed exploit attempts will likely result in denial-of-service conditions.

Affected Products

Adobe flash_player

References

BugTraq: 10057 53887

CVE: CVE-2012-2039

Short Name
HTTP:STC:ACTIVEX:FLASH-PLY-NULL
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX Adobe CVE-2012-2039 Dereference Flash Null Player bid:10057 bid:53887
Release Date
08/03/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Red_hat

Suse

Adobe

CVSS Score

9.3

Found a potential security threat?