Adobe Flash - MovieClip.duplicateMovieClip Use-After-Free
Author: Google Security Research
type: dos
platform: windows
port:
date_added: 2016-05-06
date_updated: 2016-05-06
verified: 1
codes: CVE-2016-1011
tags:
aliases:
screenshot_url:
application_url:
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=759
There is a use-after-free in MovieClip.duplicateMovieClip.If an action associated with the MovieClip frees the clip provided as the initObject parameter to the call, it will be used after it is freed.A PoC is attached.
Proof of Concept:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39779.zip