CVE-2008-4401

Description

ActionScript in Adobe Flash Player 9.0.124.0 and earlier does not require user interaction in conjunction with (1) the FileReference.browse operation in the FileReference upload API or (2) the FileReference.download operation in the FileReference download API, which allows remote attackers to create a browse dialog box, and possibly have unspecified other impact, via an SWF file.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
8.676

Associated Vulnerability

VulnerabilityOS Platform
Upgrade Adobe flash player 9.0.124.0 to latest versionWindows
Vulnerabilities CVE-2008-4401,CVE-2008-4503 are affected in Adobe Flash Player Plugin 9.0.124.0Windows
Vulnerabilities CVE-2008-4401,CVE-2008-4503 are affected in Adobe Flash Player PPAPI 9.0.124.0Windows
Multiple Vulnerabilities are affected in Adobe Flash Player 11 ActiveX 9.0.124.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234