VID |
28204 |
Severity |
40 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
A version of Macromedia Flash Player before 7.0.70.0 / 8.0.35.0 / 9.0.47.0 has been installed on the host. Macromedia Flash Player versions 7.x prior to 7.0.70.0 versions 8.x prior to 8.0.35.0 and versions 9.x prior to 9.0.47.0 could allow a remote attacker to execute arbitrary code on the system via a specially-crafted SWF file. In addition, it might also allow a remote attacker to perform arbitrary HTTP requests facilitating cross-site request forgery, information disclosure, and other attacks against a user who visits a malicious web site.
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: http://www.adobe.com/support/security/bulletins/apsb07-12.html http://www.mindedsecurity.com/en/labs/advisories/MSA01110707 http://www.frsirt.com/english/advisories/2007/2497 http://securitytracker.com/alerts/2007/Jul/1018359.html http://secunia.com/advisories/26027 http://www.kb.cert.org/vuls/id/730785 http://www.kb.cert.org/vuls/id/138457
* Platforms Affected: Adobe Systems Incorporated, Macromedia Flash Player for Windows versions prior to 7.0.70.0 Adobe Systems Incorporated, Macromedia Flash Player for Windows versions prior to 8.0.35.0 Adobe Systems Incorporated, Macromedia Flash Player for Windows versions prior to 9.0.47.0 Apple Mac OS X Any version Linux Any version Microsoft Windows Any version |
Recommendation |
Upgrade to the latest version of Macromedia Flash Player (9.0.47.0 or 8.0.35.0 or 7.0.70.0 or later), available from the Adobe Web site at http://www.adobe.com/shockwave/download/download.cgi?P1_Prod_Version=ShockwaveFlash |
Related URL |
CVE-2007-3456,CVE-2007-3457 (CVE) |
Related URL |
24856 (SecurityFocus) |
Related URL |
35337,35338 (ISS) |
|