First published: Tue Aug 14 2007(Updated: )
ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEvent error to determine whether a port is open or not. NOTE: 9.0.115.0 introduces support for a workaround, but does not fix the vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player for Internet Explorer 11 | <=9.0.114.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4324 is considered a critical vulnerability due to its potential to bypass security measures and expose sensitive information.
To mitigate CVE-2007-4324, update Adobe Flash Player to version 9.0.124.0 or later.
CVE-2007-4324 affects Adobe Flash Player versions up to and including 9.0.114.0.
CVE-2007-4324 allows remote attackers to conduct port scanning and potentially access sensitive data by exploiting Flash (SWF) movies.
Disabling or uninstalling Adobe Flash Player can serve as a temporary workaround to protect against CVE-2007-4324.