ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEvent error to determine whether a port is open or not. NOTE: 9.0.115.0 introduces support for a workaround, but does not fix the vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Flash Apsb07 20 | — | Upgrade to Adobe Flash Player version 9.0.115.0 for LinuxUpgrade to Adobe Flash Player version 9.0.115.0 for WindowsUpgrade to Adobe Flash Player version 9.0.115.0 for Mac OS X | Jul 11, 2013 | Aug 13, 2007 |
| Adobe Flash Apsb08 18 | — | Upgrade to Adobe Flash Player version 10.0.12.36 for LinuxUpgrade to Adobe Flash Player version 9.0.151.0 for WindowsUpgrade to Adobe Flash Player version 9.0.151.0 for LinuxUpgrade to Adobe Flash Player version 10.0.12.36 for WindowsUpgrade to Adobe Flash Player version 10.0.12.36 for Mac OS XUpgrade to Adobe Flash Player version 9.0.151.0 for Mac OS X | Jul 11, 2013 | Aug 13, 2007 |
| Apple Osx Flashplayerplugin | — | Apply OS X security update 2008-008Upgrade macOS to the latest version | Dec 16, 2011 | Aug 13, 2007 |
| Freebsd | — | Upgrade linux-flashplugin | Dec 10, 2025 | Oct 17, 2008 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Aug 13, 2007 |
| Suse | — | Upgrade suse-releaseUpgrade flash-player | Feb 17, 2015 | Aug 13, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub