Intrusion Prevention

Adobe.Flash.FileReference.Policy.Bypass

Description

This indicates an attack attempt to exploit a Cross Domain Policy Bypass vulnerability in Adobe Flash Player.
The vulnerability is due to insufficient sanitizing of cross domain policy in the application. A remote attacker can exploit this to bypass cross domain policy and upload arbitrary files onto vulnerability system.

Affected Products

Adobe Flash Player 16.0.0.305 and earlier versions
Adobe Flash Player 13.0.0.269 and earlier 13.x versions
Adobe Flash Player 11.2.202.442 and earlier 11.x versions

Impact

Security Bypass: Remote attackers can bypass security checks of vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor.
https://helpx.adobe.com/security/products/flash-player/apsb15-05.html

CVE References

CVE-2015-0337