First published: Thu Oct 09 2008(Updated: )
The Settings Manager in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to cause victims to unknowingly click on a link or dialog via access control dialogs disguised as normal graphical elements, as demonstrated by hijacking the camera or microphone, and related to "clickjacking."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player for Internet Explorer 11 | =8.0.24.0 | |
Adobe Flash Player for Internet Explorer 11 | <=9.0.124.0 | |
Adobe Flash Player for Internet Explorer 11 | =7.1.1 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.63 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.70.0 | |
Adobe Flash Player for Internet Explorer 11 | =8.0.35.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.114.0 | |
Adobe Flash Player for Internet Explorer 11 | =8 | |
Adobe Flash Player for Internet Explorer 11 | =7.0_r67 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.69.0 | |
Adobe Flash Player for Internet Explorer 11 | =7.0 | |
Adobe Flash Player for Internet Explorer 11 | =7.2 | |
Adobe Flash Player for Internet Explorer 11 | =7.0_r67 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.115.0 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.25 | |
Adobe Flash Player for Internet Explorer 11 | =8.0 | |
Adobe Flash Player for Internet Explorer 11 | =8.0.39.0 | |
Adobe Flash Player for Internet Explorer 11 | =8.0.34.0 | |
Adobe Flash Player for Internet Explorer 11 | =8 | |
Adobe Flash Player for Internet Explorer 11 | =7.1 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.1 | |
Adobe Flash Player for Internet Explorer 11 | =7.0.63 | |
Adobe Flash Player for Internet Explorer 11 | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4503 is considered a critical vulnerability that allows remote attackers to perform clickjacking attacks.
To fix CVE-2008-4503, upgrade to Adobe Flash Player version 10.0.22.87 or later where the vulnerability is patched.
CVE-2008-4503 specifically affects Adobe Flash Player versions 9.0.124.0 and earlier, including earlier major versions.
CVE-2008-4503 can be exploited by deceiving users into clicking on different graphical elements that lead to unintended actions.
Yes, using outdated Adobe Flash Player versions puts you at high risk of clickjacking and other security threats associated with CVE-2008-4503.