This talk will introduce Use-After-Use-After-Free (UAUAF), a novel and relatively universal exploitation technique for UAF vulnerabilities in Adobe Flash. By leveraging a sequence of object occupations and releases, UAUAF can transform a UAF into a multi-class type confusion. Full memory access is gained upon the mitigations recently added by Adobe.
by Guanxing Wen
Full Abstract: https://www.blackhat.com/eu-16/briefings/schedule/#use-after-use-after-free-exploit-uaf-by-generating-your-own-4584