First published: Wed Sep 09 2015(Updated: )
Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6680.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Shockwave Player | <=12.1.9.160 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6681 is considered critical due to its potential to allow attackers to execute arbitrary code.
To fix CVE-2015-6681, upgrade Adobe Shockwave Player to version 12.2.0.162 or later.
Adobe Shockwave Player versions prior to 12.2.0.162 are vulnerable to CVE-2015-6681.
CVE-2015-6681 can facilitate arbitrary code execution and cause denial of service through memory corruption.
If you cannot upgrade, it is advisable to limit the use of Adobe Shockwave Player and employ additional security measures.