This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Community Information

Macromedia Flash Subject to Arbitrary Code Execution

1 min read

This thread's last reply is from November 9, 2005, 12:48 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Quoting from eEye's advisory on this vulnerability:
eEye Digital Security has discovered a vulnerability in Macromedia Flash Player versions 6 and 7 that will allow an attacker to run arbitrary code in the context of the logged in user. An array boundary condition may be violated by a malicious SWF file in order to redirect execution into attacker-supplied data.

Macromedia has released an update that resolves this vulnerability in Flash Player 7.0.19.0 and earlier versions. Their description of the problem and a link to the update can be found here.

Jim
zero reply bump