Netskope Threat Labs

FILE-FLASH Adobe Flash Player RTMP malformed onStatus message type confusion attempt

IPS-CFW

2 SIDs: 26429, 26430

Detects a malicious Real-Time Messaging Protocol response exploiting CVE-2013-2555, a type confusion in Flash Player's status message handling that can allow code execution. The rule matches the malformed status messages that public exploits use to confuse the engine.