Adobe Flash Player AS3 ConvolutionFilter Use-After-Free Exploit

This module exploits a Use-After-Free vulnerability in Adobe Flash Player. The specific flaw exists within the processing of AS3 ConvolutionFilter objects. By manipulating the matrix property of a ConvolutionFilter object, an attacker can force a dangling pointer to be reused after it has been freed. An attacker can leverage this vulnerability to execute code under the context of the current process. This vulnerability was one of the 2015's Pwn2Own challenges.
Exploit type: 
Platform: 
Vulnerabilty ID: 
CVE-2015-0349
Product Version: 
2014_R2
Released Date: 
Wednesday, July 15, 2015 - 00:00