// For flags

CVE-2007-6019

Adobe Flash Player DeclareFunction2 Invalid Object Use Vulnerability

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.

Adobe Flash Player 9.0.115.0 y versiones anteriores, y 8.0.39.0 y versiones anteriores, permite a atacantes remotos ejecutar código de su elección a través de un fichero SWF con una etiqueta modificada DeclareFunction2 Actionscript, lo cual evita que un objeto sea instanciado adecuadamente.

This vulnerability allows remote attackers to execute code on vulnerable installations of Adobe's Flash Player. User interaction is required in that a user must visit a malicious web site.
The specific flaw exists when the Flash player attempts to access embedded Actionscript objects that have not been properly instantiated. In order for exploitation to occur, an attacker would have to modify a DeclareFunction2 Actionscript tag within an SWF file. Exploitation of this vulnerability can result in arbitrary code execution under the context of the currently logged in user.

*Credits: Javier Vicente VallejoShane Macaulay CanSecWest 2008 PWN2OWN Winner
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-11-19 CVE Reserved
  • 2008-04-08 CVE Published
  • 2008-04-08 First Exploit
  • 2024-08-07 CVE Updated
  • 2024-10-20 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-20: Improper Input Validation
CAPEC
References (25)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Adobe
Search vendor "Adobe"
Air
Search vendor "Adobe" for product "Air"
1.0
Search vendor "Adobe" for product "Air" and version "1.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash
Search vendor "Adobe" for product "Flash"
basic
Search vendor "Adobe" for product "Flash" and version "basic"
8
Affected
Adobe
Search vendor "Adobe"
Flash
Search vendor "Adobe" for product "Flash"
professional
Search vendor "Adobe" for product "Flash" and version "professional"
8
Affected
Adobe
Search vendor "Adobe"
Flash
Search vendor "Adobe" for product "Flash"
professional
Search vendor "Adobe" for product "Flash" and version "professional"
cs3
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
<= 9.0.115.0
Search vendor "Adobe" for product "Flash Player" and version " <= 9.0.115.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
7.0
Search vendor "Adobe" for product "Flash Player" and version "7.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
7.0.1
Search vendor "Adobe" for product "Flash Player" and version "7.0.1"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
7.0.25
Search vendor "Adobe" for product "Flash Player" and version "7.0.25"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
7.0.63
Search vendor "Adobe" for product "Flash Player" and version "7.0.63"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
7.0.69.0
Search vendor "Adobe" for product "Flash Player" and version "7.0.69.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
7.0.70.0
Search vendor "Adobe" for product "Flash Player" and version "7.0.70.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
7.0_r67
Search vendor "Adobe" for product "Flash Player" and version "7.0_r67"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
7.1
Search vendor "Adobe" for product "Flash Player" and version "7.1"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
7.1.1
Search vendor "Adobe" for product "Flash Player" and version "7.1.1"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
7.2
Search vendor "Adobe" for product "Flash Player" and version "7.2"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
8
Search vendor "Adobe" for product "Flash Player" and version "8"
pro
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
8
Search vendor "Adobe" for product "Flash Player" and version "8"
professional
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
8.0
Search vendor "Adobe" for product "Flash Player" and version "8.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
8.0
Search vendor "Adobe" for product "Flash Player" and version "8.0"
basic
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
8.0
Search vendor "Adobe" for product "Flash Player" and version "8.0"
pro
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
8.0.24.0
Search vendor "Adobe" for product "Flash Player" and version "8.0.24.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
8.0.34.0
Search vendor "Adobe" for product "Flash Player" and version "8.0.34.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
8.0.35.0
Search vendor "Adobe" for product "Flash Player" and version "8.0.35.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
8.0.39.0
Search vendor "Adobe" for product "Flash Player" and version "8.0.39.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0
Search vendor "Adobe" for product "Flash Player" and version "9.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0.16
Search vendor "Adobe" for product "Flash Player" and version "9.0.16"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0.16
Search vendor "Adobe" for product "Flash Player" and version "9.0.16"
windows
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0.18d60
Search vendor "Adobe" for product "Flash Player" and version "9.0.18d60"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0.20
Search vendor "Adobe" for product "Flash Player" and version "9.0.20"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0.20.0
Search vendor "Adobe" for product "Flash Player" and version "9.0.20.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0.28
Search vendor "Adobe" for product "Flash Player" and version "9.0.28"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0.28.0
Search vendor "Adobe" for product "Flash Player" and version "9.0.28.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0.31
Search vendor "Adobe" for product "Flash Player" and version "9.0.31"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0.31.0
Search vendor "Adobe" for product "Flash Player" and version "9.0.31.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0.45.0
Search vendor "Adobe" for product "Flash Player" and version "9.0.45.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0.47.0
Search vendor "Adobe" for product "Flash Player" and version "9.0.47.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0.48.0
Search vendor "Adobe" for product "Flash Player" and version "9.0.48.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0.112.0
Search vendor "Adobe" for product "Flash Player" and version "9.0.112.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0.114.0
Search vendor "Adobe" for product "Flash Player" and version "9.0.114.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0.124.0
Search vendor "Adobe" for product "Flash Player" and version "9.0.124.0"
-
Affected
Adobe
Search vendor "Adobe"
Flash Player
Search vendor "Adobe" for product "Flash Player"
9.0.155.0
Search vendor "Adobe" for product "Flash Player" and version "9.0.155.0"
-
Affected
Adobe
Search vendor "Adobe"
Flex
Search vendor "Adobe" for product "Flex"
3.0
Search vendor "Adobe" for product "Flex" and version "3.0"
-
Affected