Korean
<< Back
VID 28204
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description A version of Macromedia Flash Player before 7.0.70.0 / 8.0.35.0 / 9.0.47.0 has been installed on the host. Macromedia Flash Player versions 7.x prior to 7.0.70.0 versions 8.x prior to 8.0.35.0 and versions 9.x prior to 9.0.47.0 could allow a remote attacker to execute arbitrary code on the system via a specially-crafted SWF file. In addition, it might also allow a remote attacker to perform arbitrary HTTP requests facilitating cross-site request forgery, information disclosure, and other attacks against a user who visits a malicious web site.

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://www.adobe.com/support/security/bulletins/apsb07-12.html
http://www.mindedsecurity.com/en/labs/advisories/MSA01110707
http://www.frsirt.com/english/advisories/2007/2497
http://securitytracker.com/alerts/2007/Jul/1018359.html
http://secunia.com/advisories/26027
http://www.kb.cert.org/vuls/id/730785
http://www.kb.cert.org/vuls/id/138457

* Platforms Affected:
Adobe Systems Incorporated, Macromedia Flash Player for Windows versions prior to 7.0.70.0
Adobe Systems Incorporated, Macromedia Flash Player for Windows versions prior to 8.0.35.0
Adobe Systems Incorporated, Macromedia Flash Player for Windows versions prior to 9.0.47.0
Apple Mac OS X Any version
Linux Any version
Microsoft Windows Any version
Recommendation Upgrade to the latest version of Macromedia Flash Player (9.0.47.0 or 8.0.35.0 or 7.0.70.0 or later), available from the Adobe Web site at http://www.adobe.com/shockwave/download/download.cgi?P1_Prod_Version=ShockwaveFlash
Related URL CVE-2007-3456,CVE-2007-3457 (CVE)
Related URL 24856 (SecurityFocus)
Related URL 35337,35338 (ISS)