Interaction error between Adobe Flash and multiple Universal Plug and Play (UPnP) services allow remote attackers to perform Cross-Site Request Forgery (CSRF) style attacks by using the Flash navigateToURL function to send a SOAP message to a UPnP control point, as demonstrated by changing the primary DNS server.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Flashplayerplugin | — | Apply OS X security update 2008-003Upgrade macOS to the latest version | Dec 16, 2011 | Apr 2, 2008 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Apr 2, 2008 |
| Suse | — | Upgrade flash-playerUpgrade suse-release | Feb 17, 2015 | Apr 2, 2008 |
| Ubuntu | — | Upgrade flashplugin-nonfree | Nov 19, 2024 | Apr 2, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub