Adobe Flash Zero day

February 3, 2015

A critical vulnerability (CVE-2015-0313) exists in Adobe Flash Player 16.0.0.296 and earlier versions for Windows and Macintosh. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.This vulnerability is being actively exploited in the wild via drive-by-download attacks against systems running Internet Explorer and Firefox on Windows 8.1 and below.

Dell SonicWALL Threat Research Team has researched this vulnerability (CVE-2015-0313) and released the following signature to protect their customers.

  • SPY 4397 : Malformed-File swf.OT.28