Vulnerability Name:

CVE-2019-8070 (CCN-166562)

Assigned:2019-09-10
Published:2019-09-10
Updated:2021-11-22
Summary:Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Use after free vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-416
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2019-8070

Source: XF
Type: UNKNOWN
adobe-flash-cve20198070-code-exec(166562)

Source: CCN
Type: Adobe Security Bulletin APSB19-46
Security updates available for Adobe Flash Player

Source: CONFIRM
Type: Vendor Advisory
https://helpx.adobe.com/security/products/flash-player/apsb19-46.html

Source: GENTOO
Type: Third Party Advisory
GLSA-201911-05

Source: CCN
Type: ZDI-19-818
Adobe Flash Player PSDK Use-After-Free Remote Code Execution Vulnerability

Source: CCN
Type: ZDI-19-818
Adobe Flash Player PSDK Use-After-Free Remote Code Execution Vulnerability

Vulnerable Configuration:Configuration 1:
  • cpe:/a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* (Version <= 32.0.0.238)
  • AND
  • cpe:/o:apple:macos:-:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:-:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:adobe:flash_player:*:*:*:*:*:chrome:*:* (Version <= 32.0.0.238)
  • AND
  • cpe:/o:google:chrome_os:-:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:-:*:*:*:*:*:*:*
  • OR cpe:/o:apple:macos:-:*:*:*:*:*:*:*
  • OR cpe:/o:linux:linux_kernel:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:adobe:flash_player:*:*:*:*:*:edge:*:* (Version <= 32.0.0.207)
  • OR cpe:/a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* (Version <= 32.0.0.207)
  • AND
  • cpe:/o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_10:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:adobe:flash_player:32.0.0.238:*:*:*:*:chrome:*:*
  • OR cpe:/a:adobe:flash_player:32.0.0.238:*:*:*:*:linux:*:*
  • OR cpe:/a:adobe:flash_player:32.0.0.207:*:*:*:*:chrome:*:*
  • OR cpe:/a:adobe:flash_player:32.0.0.207:*:*:*:*:chrome:*:*
  • OR cpe:/a:adobe:flash_player:32.0.0.238:*:*:*:*:chrome:*:*
  • OR cpe:/a:adobe:flash_player:32.0.0.238:*:*:*:*:chrome:*:*
  • AND
  • cpe:/o:microsoft:windows_8:-:-:-:*:-:-:x32:*
  • OR cpe:/o:microsoft:windows_8:*:*:*:*:*:*:x64:*
  • OR cpe:/o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_rt:-:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_8.1:-:-:-:*:-:-:x32:*
  • OR cpe:/o:microsoft:windows_8.1:*:*:*:*:*:*:x64:*
  • OR cpe:/o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    adobe flash player desktop runtime *
    apple macos -
    linux linux kernel -
    microsoft windows -
    adobe flash player *
    google chrome os -
    microsoft windows -
    apple macos -
    linux linux kernel -
    adobe flash player *
    adobe flash player *
    microsoft windows 8.1 -
    microsoft windows 10 -
    adobe flash player 32.0.0.238
    adobe flash player 32.0.0.238
    adobe flash player 32.0.0.207
    adobe flash player 32.0.0.207
    adobe flash player 32.0.0.238
    adobe flash player 32.0.0.238
    microsoft windows 8 - -
    microsoft windows 8 *
    microsoft windows server 2012
    microsoft windows rt -
    microsoft windows 8.1 - -
    microsoft windows 8.1 *
    microsoft windows server 2012 r2
    microsoft windows rt 8.1 *