At the end of 2017 we discovered an Adobe Flash Player zero day vulnerability (CVE-2017-11292) that was used by the BlackOasis APT. This shows that Adobe Flash Player still is a good target for threat actors. CVE-2017-11292 is a particularly interesting logic bug that lead to type-confusion vulnerability, and there are no public reports describing it. In our presentation we will cover the following things:1. What exploitation techniques are currently used by threat actors in Flash exploits2. A detailed description of CVE-2017-112923. Also we will talk about how to find new vulnerabilities in Adobe Flash PlayerWe will present and release our self-made ActionScript3 processor module and debug plugin for IDA Pro. These tools complement each other, and have shown some good results in debugging exploits in-the-wild.We analyzed AVM and discovered how to boost analysis with the rich possibilities of IDA Pro and API.