CVE-2007-4324: Medium severity Adobe Flash Player vulnerability
ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEvent error to determine whether a port is open or not. NOTE: 9.0.115.0 introduces support for a workaround, but does not fix the vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4324?
CVE-2007-4324 is considered a critical vulnerability due to its potential to bypass security measures and expose sensitive information.
How do I fix CVE-2007-4324?
To mitigate CVE-2007-4324, update Adobe Flash Player to version 9.0.124.0 or later.
What systems are affected by CVE-2007-4324?
CVE-2007-4324 affects Adobe Flash Player versions up to and including 9.0.114.0.
What type of attack is associated with CVE-2007-4324?
CVE-2007-4324 allows remote attackers to conduct port scanning and potentially access sensitive data by exploiting Flash (SWF) movies.
Is there a workaround for CVE-2007-4324?
Disabling or uninstalling Adobe Flash Player can serve as a temporary workaround to protect against CVE-2007-4324.