Security Advisory
  • Microsoft Windows Flash Player Multiple Vulnerabilities Reported Date: 13-01-10
Rated Level: Moderate
Impact: System Access,Remotely Exploitable
Affected Software: Microsoft Windows XP Home Edition
Microsoft Windows XP Professional
Description: A vulnerability in Windows XP, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a use-after-free error in the bundled version of Flash Player when unloading Flash objects while these are still being accessed using script code. This can be exploited to corrupt memory via a specially crafted web page.

Successful exploitation allows execution of arbitrary code.

The vulnerability is confirmed in Flash Player bundled with a fully patched Windows XP SP2 and is also confirmed in an old version 6.0.79 of Adobe Flash Player.

NOTE: The version of Flash Player bundled with Windows XP is also affected by a number of other vulnerabilities previously disclosed and fixed in later versions of Adobe Flash Player.


Note: Carsten Eiram and Dyon Balding, Secunia Research
Solution: Uninstall the bundled version of Flash Player and optionally install the latest supported version of Flash Player from Adobe.
References: How to remove the Flash Player ActiveX control:
http://kb2.adobe.com/cps/127/tn_12727.html

How to uninstall the Adobe Flash Player plug-in and ActiveX control:
http://kb2.adobe.com/cps/141/tn_14157.html
Feedback: If you have additional information or corrections for this security advisory please contact us at advisory(at)triviasecurity.org
Security Advisories by Month (2010)
Aug (4) Jul (3) Apr (5) Mar (3) Jan (8)
TS Promotion