Release DateDec 08, 2009 |
Severitycritical |
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems. |
DescriptionThis indicates an attack attempt to exploit a remote code-execution vulnerability in Adobe Flash Player.The vulnerability is caused by an error when parsing a JPEG file embedded in an SWF file. It can be exploited via a crafted SWF file, leading to remote code execution. |
Affected ProductsAdobe Flash Player version 10.0.32.18 and the prior |
Recommended ActionsRefer to the vendor's web site for the suggested workaround:http://www.adobe.com/support/security/bulletins/apsb09-19.html |
Coverage IPS
VCM |
Common Vulnerabilities and Exposures (CVE)CVE-2009-3794 |
Reference/shttp://www.zerodayinitiative.com/advisories/ZDI-09-092/http://www.adobe.com/support/security/bulletins/apsb09-19.html |