Vulnerability Note VU#259425
Adobe Flash vulnerability affects Flash Player and other Adobe products
Adobe Flash contains a vulnerability that may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system. Adobe Flash Player, Reader, Acrobat, and other products that include Flash support are affected.
Adobe Flash is a widely deployed multimedia platform typically used to provide content in web sites. Adobe Flash Player, Reader, Acrobat, and other Adobe products include Flash support.
Adobe Flash Player contains a code execution vulnerability. An attacker may be able to trigger this vulnerability by convincing a user to open a specially crafted Flash (SWF) file. The SWF file could be hosted or embedded in a web page or contained in a Portable Document Format (PDF) file. If an attacker can take control of a website or web server, trusted sites may exploit this vulnerability.
By convincing a user to view a specially crafted HTML document (e.g., a web page or an HTML email message or attachment), PDF file, Microsoft Office document, or any other document that supports embedded SWF content, an attacker may be able to execute arbitrary code.
Apply an update
Systems Affected (Learn More)
|Vendor||Status||Date Notified||Date Updated|
|Adobe||Affected||-||23 Jul 2009|
CVSS Metrics (Learn More)
This vulnerability was reported on the Adobe PSIRT blog . Thanks to Department of Defense Cyber Crime Center/DCISE for information used in this document.
This document was written by Chris Taschner, Will Dormann, Chad Dougherty, and Art Manion.
- CVE IDs: CVE-2009-1862
- US-CERT Alert: TA09-204A
- Date Public: 22 Jul 2009
- Date First Published: 22 Jul 2009
- Date Last Updated: 07 Aug 2009
- Severity Metric: 35.34
- Document Revision: 48
If you have feedback, comments, or additional information about this vulnerability, please send us email.