cbcvebase.
CVE-2007-6019
published 2008-04-09

CVE-2007-6019: Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified…

PriorityP263critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
59.77%
99.0th percentile
Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
adobeair
adobeflash
adobeflash
adobeflash_player<= 9.0.115.0
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player
adobeflash_player

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/31630.rar
  • Detect exploitation attempts targeting the DeclareFunction2 ActionScript tag in SWF files; malicious SWF files will contain a modified/malformed DeclareFunction2 tag that prevents proper object instantiation.
  • Flag delivery or execution of SWF files exploiting this vulnerability; the attack vector is a specially crafted .SWF file delivered to the Flash Player.
  • ·Vulnerable versions are Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier; Flash Player 9.0.124.0 is the patched version. Detections should target environments still running these older versions.
  • ·Adobe Flash Player 9.0.124.0 addresses this vulnerability; systems upgraded to this version or later are not affected.

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.