Netskope Threat Labs

FILE-FLASH Adobe Flash malformed RTMP response attempt

IPS-CFW

3 SIDs: 24138, 24139, 24140

Detects a malicious Real-Time Messaging Protocol response exploiting CVE-2012-0779, memory corruption in Flash Player's media server handling that can allow code execution. The rule matches the malformed error response that public exploits use to corrupt memory.