CVE-2019-7837: Adobe Flash Player PSDK Use-After-Free Remote Code Execution Vulnerability
Adobe Flash Player versions 32.0.0.171 and earlier, 32.0.0.171 and earlier, and 32.0.0.171 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
Other sources
Adobe Security Bulletin APSB19-26 for Adobe Flash Player describes a flaw that can possibly lead to arbitrary code execution when Flash Player is used to play a specially crafted SWF file:
Use After Free -- CVE-2019-7837
External References:
https://helpx.adobe.com/security/products/flash-player/apsb19-26.html
— Red Hat
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of objects in the PSDK namespace. By performing actions in ActionScript, an attacker can cause a pointer to be reused after it has been freed. An attacker can leverage this vulnerability to execute code in the context of the current process.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-7837?
CVE-2019-7837 is a vulnerability that allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash Player.
How severe is CVE-2019-7837?
CVE-2019-7837 has a severity rating of critical with a score of 8.8.
How can the CVE-2019-7837 vulnerability be exploited?
To exploit CVE-2019-7837, user interaction is required, meaning the target must visit a malicious page or open a malicious file.
What software is affected by CVE-2019-7837?
Adobe Flash Player versions up to and including 32.0.0.171 are affected by CVE-2019-7837.
How can I fix CVE-2019-7837?
To fix CVE-2019-7837, update Adobe Flash Player to version 32.0.0.192 or higher.