FILE-FLASH -- Snort has detected suspicious traffic via the Adobe Flash Player. Flash is a common target of code execution, overflow, DoS, and memory corruption attacks in particular, via swifs, action scripts, etc. Many networks block Flash altogether; the application will be deprecated in 2020.
FILE-FLASH Adobe Flash Player malformed ATF heap overflow attempt
This event is generated when an attempt to exploit an ATF parsing heap buffer overflow in Adobe Flash Player is detected.
Attempted User Privilege Gain
Ease of Attack:
What To Look For
No public information
No known false positives
Cisco Talos Intelligence Group
MITRE ATT&CK Framework
For reference, see the MITRE ATT&CK vulnerability types here:
CVE Additional Information
CVE-2016-1002Adobe Flash Player before 184.108.40.2063 and 19.x through 21.x before 220.127.116.11 on Windows and OS X and before 18.104.22.1687 on Linux, Adobe AIR before 22.214.171.124, Adobe AIR SDK before 126.96.36.199, and Adobe AIR SDK & Compiler before 188.8.131.52 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0960, CVE-2016-0961, CVE-2016-0962, CVE-2016-0986, CVE-2016-0989, CVE-2016-0992, and CVE-2016-1005.
||Ease of Access||