Home / bulletins MS06-069: Vulnerabilities in Macromedia Flash Player from Adobe Could Allow Remote Code Execution (923789) - Version:2.0
Posted on 14 May 2008
Severity Rating: Critical - Revision Note: V2.0 (May 13, 2008): Bulletin updated to add Windows XP Service Pack 3 as affected software. This is a detection update only. There were no changes to the binaries.Summary: This update resolves a privately reported vulnerability in Macromedia Flash Player from Adobe, version 6.0.84.0 and earlier. Macromedia Flash Player is a third party software application that also was redistributed with Microsoft Windows XP Service Pack 2, Windows XP Service Pack 3, and Microsoft Windows XP Professional x64 Edition. The vulnerability is documented in the Vulnerability Details section of this bulletin. The Adobe Security Bulletin APSB06-11, issued September 12, 2006, describes the vulnerabilities and provides the download locations for customers who have installed Flash Player 7 and higher so that you can install the appropriate update based on the version of Flash Player you are using. Customers that have followed the guidance in the Adobe Security Bulletinare not at risk from the vulnerability. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. We recommend that customers apply the update immediately.