CVE-2007-4324
Description
ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEvent error to determine whether a port is open or not. NOTE: 9.0.115.0 introduces support for a workaround, but does not fix the vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
ActionScript 3 in Flash Player 9.0.47.0 and earlier allows remote attackers to bypass Security Sandbox and port scan via timing discrepancies.
Vulnerability
A flaw in ActionScript 3 (AS3) in Adobe Flash Player versions 9.0.47.0 and earlier, as well as other versions up to 9.0.124.0, allows remote attackers to bypass the Security Sandbox Model. The vulnerability is triggered when a Flash (SWF) movie specifies a connection to a host or port. The attacker can then exploit timing discrepancies from the SecurityErrorEvent error to determine whether a remote port is open or closed, effectively conducting a port scan without proper security restrictions [1][2][3][4].
Exploitation
An attacker only needs to craft a malicious SWF file that targets a remote host and port. The SWF file attempts a connection; depending on the timing of the SecurityErrorEvent, the attacker can infer the state of the port. No authentication or special network position is required—the victim simply loads the SWF in a browser with an affected Flash Player version [1][2][3][4].
Impact
Successful exploitation allows a remote attacker to bypass the Security Sandbox Model, obtain sensitive information about the target network (e.g., which ports are open on a host), and perform port scans. This information disclosure can aid further attacks. The attacker does not gain code execution or file write access directly, but the breach of the sandbox compromises the intended security boundaries of Flash Player [1][2][3][4].
Mitigation
Adobe Flash Player 9.0.115.0 introduced a workaround that partially mitigates the issue by altering the timing behavior, but the vulnerability was not fully fixed. Patched versions were eventually released as part of security updates; for example, Red Hat issued RHSA-2008-0980 to update the flash-plugin package. Users should upgrade to a version later than 9.0.124.0 that completely addresses the flaw. No workaround is available for vulnerable versions other than upgrading [1][2][3][4].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 9.0.47.0, 9.0.124.0 and earlier
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
35- secunia.com/advisories/28157nvdVendor Advisory
- secunia.com/advisories/28161nvdVendor Advisory
- www.us-cert.gov/cas/techalerts/TA07-355A.htmlnvdUS Government Resource
- kb.adobe.com/selfservice/viewContent.donvd
- lists.opensuse.org/opensuse-security-announce/2007-12/msg00007.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.htmlnvd
- scan.flashsec.orgnvd
- secunia.com/advisories/28213nvd
- secunia.com/advisories/28570nvd
- secunia.com/advisories/30507nvd
- secunia.com/advisories/32270nvd
- secunia.com/advisories/32448nvd
- secunia.com/advisories/32702nvd
- secunia.com/advisories/32759nvd
- secunia.com/advisories/33390nvd
- securityreason.com/securityalert/2995nvd
- securitytracker.com/idnvd
- sunsolve.sun.com/search/document.donvd
- sunsolve.sun.com/search/document.donvd
- support.avaya.com/elmodocs2/security/ASA-2008-440.htmnvd
- support.avaya.com/elmodocs2/security/ASA-2009-020.htmnvd
- support.nortel.com/go/main.jspnvd
- www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.htmlnvd
- www.adobe.com/support/security/bulletins/apsb07-20.htmlnvd
- www.adobe.com/support/security/bulletins/apsb08-18.htmlnvd
- www.gentoo.org/security/en/glsa/glsa-200801-07.xmlnvd
- www.redhat.com/support/errata/RHSA-2007-1126.htmlnvd
- www.redhat.com/support/errata/RHSA-2008-0945.htmlnvd
- www.redhat.com/support/errata/RHSA-2008-0980.htmlnvd
- www.securityfocus.com/archive/1/475961/100/0/threadednvd
- www.securityfocus.com/bid/25260nvd
- www.vupen.com/english/advisories/2007/4258nvd
- www.vupen.com/english/advisories/2008/1724/referencesnvd
- www.vupen.com/english/advisories/2008/2838nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11874nvd
News mentions
0No linked articles in our index yet.