CVE-2008-4503: Medium severity macromedia flash player vulnerability

Published Oct 9, 2008
·
Updated

The Settings Manager in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to cause victims to unknowingly click on a link or dialog via access control dialogs disguised as normal graphical elements, as demonstrated by hijacking the camera or microphone, and related to "clickjacking."

Affected Software

23 affected components
Adobe Flash Player=8.0.24.0
Adobe Flash Player<=9.0.124.0
Adobe Flash Player=7.1.1
Adobe Flash Player=7.0.63
Adobe Flash Player=7.0.70.0
Adobe Flash Player=8.0.35.0
Adobe Flash Player=9.0.114.0
Adobe Flash Player=8
Adobe Flash Player=7.0_r67
Adobe Flash Player=7.0.69.0
Adobe Flash Player=7.0
Adobe Flash Player=7.2
Adobe Flash Player=7.0_r67
Adobe Flash Player=9.0.115.0
Adobe Flash Player=7.0.25
Adobe Flash Player=8.0
Adobe Flash Player=8.0.39.0
Adobe Flash Player=8.0.34.0
Adobe Flash Player=8
Adobe Flash Player=7.1
Adobe Flash Player=7.0.1
Adobe Flash Player=7.0.63
Adobe Flash Player=9.0

Event History

Oct 9, 2008
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2008-4503?

CVE-2008-4503 is considered a critical vulnerability that allows remote attackers to perform clickjacking attacks.

2

How do I fix CVE-2008-4503?

To fix CVE-2008-4503, upgrade to Adobe Flash Player version 10.0.22.87 or later where the vulnerability is patched.

3

What does CVE-2008-4503 specifically affect?

CVE-2008-4503 specifically affects Adobe Flash Player versions 9.0.124.0 and earlier, including earlier major versions.

4

How can CVE-2008-4503 be exploited?

CVE-2008-4503 can be exploited by deceiving users into clicking on different graphical elements that lead to unintended actions.

5

Am I at risk if I use outdated Adobe Flash Player versions due to CVE-2008-4503?

Yes, using outdated Adobe Flash Player versions puts you at high risk of clickjacking and other security threats associated with CVE-2008-4503.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203