VID |
28259 |
Severity |
40 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
A version of Adobe Flash Player that is earlier than 10.0.32.18 / 9.0.246.0. Such Versions are reportedly affected by multiple vulnerabilities.
- A memory corruption vulnerability that could potentially lead to code execution. (CVE-2009-1862) - A vulnerability in the Microsoft Active Template Library (ATL) which could allow an attacker who successfully exploits the vulnerability to take control of the affected system. (CVE-2009-0901, CVE-2009-2395,CVE-2009-2493) - A privilege escalation vulnerability that could potentially lead to code execution. (CVE-2009-1863) - A heap overflow vulnerability that could potentially lead to code execution. (CVE-2009-1864) - A null pointer vulnerability that could potentially lead to code execution. (CVE-2009-1865) - A stack overflow vulnerability that could potentially lead to code execution. (CVE-2009-1866) - A clickjacking vulnerability that could allow an attacker to lure a web browser user into unknowingly clicking on a link or dialog. (CVE-2009-1867 - A URL parsing heap overflow vulnerability that could potentially lead to code execution. (CVE-2009-1868) - An integer overflow vulnerability that could potentially lead to code execution. (CVE-2009-1869) - A local sandbox vulnerability that could potentially lead to information disclosure when SWFs are saved to the hard drive. CVE-2009-1870)
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: http://www.adobe.com/support/security/bulletins/apsb09-10.html
* Platforms Affected: Adobe Systems Incorporated, Macromedia Flash Player for Windows versions 8.0.39.0 and earlier Adobe Flash Player 9.0.159.0 and 10.0.22.87 and earlier 9.x and 10.x versions. Apple Mac OS X Any version Linux Any version Microsoft Windows Any version |
Recommendation |
Upgrade to the latest version of Adobe Flash Player (9.0.246.0 or 10.0.32.18 or later), available from the Adobe Web site at http://get.adobe.com/kr/air/ |
Related URL |
CVE-2009-1862,CVE-2009-0901,CVE-2009-2493,CVE-2009-1863,CVE-2009-1864,CVE-2009-1865,CVE-2009-1866,CVE-2009-1867,CVE-2009-1868,CVE-2009-1869 (CVE) |
Related URL |
35759,35832,35846,35900,35901,35902,35903,35904,35905,35906,35907,35908 (SecurityFocus) |
Related URL |
(ISS) |
|