Showing posts with label CVE-2014-0515. Show all posts
Showing posts with label CVE-2014-0515. Show all posts

Monday, April 28, 2014

[securelist] New Flash Player 0-day (CVE-2014-0515) used in watering-hole attacks

In mid-April we detected two new SWF exploits. After some detailed analysis it was clear they didn't use any of the vulnerabilities that we already knew about. We sent the exploits off to Adobe and a few days later got confirmation that they did indeed use a 0-day vulnerability that was later labeled as CVE-2014-0515. The vulnerability is located in the Pixel Bender component, designed for video and image processing.