Adobe Flash Player Security Bypass Vulnerability (CVE-2014-4671)
2015年7月21日
危険度: 中
情報公開日: 7 21, 2015
概要
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and before 11.2.202.394 on Linux do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.
トレンドマイクロの対策
Apply associated Trend Micro DPI Rules.
対応方法
Trend Micro Deep Security DPI Rule Number: 1006138