Korean
<< Back
VID 28259
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description A version of Adobe Flash Player that is earlier than 10.0.32.18 / 9.0.246.0. Such Versions are reportedly affected by multiple vulnerabilities.

- A memory corruption vulnerability that could potentially lead to code execution. (CVE-2009-1862)
- A vulnerability in the Microsoft Active Template Library (ATL) which could allow an attacker who successfully exploits the vulnerability to take control of the affected system. (CVE-2009-0901, CVE-2009-2395,CVE-2009-2493)
- A privilege escalation vulnerability that could potentially lead to code execution. (CVE-2009-1863)
- A heap overflow vulnerability that could potentially lead to code execution. (CVE-2009-1864)
- A null pointer vulnerability that could potentially lead to code execution. (CVE-2009-1865)
- A stack overflow vulnerability that could potentially lead to code execution. (CVE-2009-1866)
- A clickjacking vulnerability that could allow an attacker to lure a web browser user into unknowingly clicking on a link or dialog. (CVE-2009-1867
- A URL parsing heap overflow vulnerability that could potentially lead to code execution. (CVE-2009-1868)
- An integer overflow vulnerability that could potentially lead to code execution. (CVE-2009-1869)
- A local sandbox vulnerability that could potentially lead to information disclosure when SWFs are saved to the hard drive. CVE-2009-1870)

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://www.adobe.com/support/security/bulletins/apsb09-10.html

* Platforms Affected:
Adobe Systems Incorporated, Macromedia Flash Player for Windows versions 8.0.39.0 and earlier
Adobe Flash Player 9.0.159.0 and 10.0.22.87 and earlier 9.x and 10.x versions.
Apple Mac OS X Any version
Linux Any version
Microsoft Windows Any version
Recommendation Upgrade to the latest version of Adobe Flash Player (9.0.246.0 or 10.0.32.18 or later), available from the Adobe Web site at http://get.adobe.com/kr/air/
Related URL CVE-2009-1862,CVE-2009-0901,CVE-2009-2493,CVE-2009-1863,CVE-2009-1864,CVE-2009-1865,CVE-2009-1866,CVE-2009-1867,CVE-2009-1868,CVE-2009-1869 (CVE)
Related URL 35759,35832,35846,35900,35901,35902,35903,35904,35905,35906,35907,35908 (SecurityFocus)
Related URL (ISS)