Vulnerability record · CVE-2007-3456 · published 11 July 2007
CVE-2007-3456: Adobe Flash Player integer overflow in FLV/SWF parsing enables code execution
Adobe · Flash Player
Adobe Flash Player 9.0.45.0 and earlier contains an integer overflow when handling large length values for Long string or XML variable types in crafted FLV or SWF files. The flaw stems from an input validation error involving a signed comparison of values assumed to be non-negative, which can corrupt memory. Successful exploitation allows remote code execution in the context of the Flash Player process.
Description
Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input validation error," including a signed comparison of values that are assumed to be non-negative.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 2.0 score of 9.3 and high EPSS percentile indicate severe impact and elevated exploitation likelihood, though no KEV listing or confirmed in-the-wild activity is present.
What it is
Adobe Flash Player 9.0.45.0 and earlier contains an integer overflow when handling large length values for Long string or XML variable types in crafted FLV or SWF files. The flaw stems from an input validation error involving a signed comparison of values assumed to be non-negative, which can corrupt memory. Successful exploitation allows remote code execution in the context of the Flash Player process.
Impact
An attacker can execute arbitrary code on the victim's system, leading to full compromise of confidentiality, integrity, and availability. The CVSS 2.0 vector (AV:N/AC:M/Au:N/C:C/I:C/A:C) reflects complete impact with no authentication required.
Attack surface
The vulnerability is reached remotely over the network by delivering a malicious FLV or SWF file, typically via a web page or direct file open. No authentication is required, but some user interaction (e.g., visiting a crafted page or opening a file) is needed to trigger parsing.
Exploitation
The record is not listed in CISA KEV, but EPSS indicates a high probability of exploitation (0.56309, 99th percentile). References include vendor advisories and US-CERT alerts, but no public exploit code or in-the-wild reports are explicitly tagged.
What to do
- Upgrade Adobe Flash Player to a version later than 9.0.45.0 as directed by Adobe security bulletin APSB07-12.
- Apply vendor patches for affected platforms (Apple, Sun, Gentoo, Novell) referenced in the advisories.
- Disable or restrict Flash Player where it is not required, and block untrusted FLV/SWF content at the network perimeter.
- Enforce browser settings that require user confirmation before running Flash content from untrusted sources.
Detection
- Monitor for processes loading Flash Player (e.g., flashplayer, npapi) spawning unexpected child processes or making outbound network connections.
- Inspect network traffic for anomalous FLV or SWF files with unusually large length fields in Long string or XML variable structures.
- Review endpoint logs for crashes or memory corruption events in Flash Player, which may indicate exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-3456 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-3456), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.