Vulnerability record · CVE-2007-6019 · published 9 April 2008
CVE-2007-6019: Adobe Flash Player Actionscript DeclareFunction2 tag memory corruption
Adobe · Air
Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, mishandle a modified DeclareFunction2 Actionscript tag in an SWF file, preventing an object from being instantiated properly. A remote attacker can supply a crafted SWF that triggers memory corruption and arbitrary code execution in the context of the player. The record does not specify the exact memory-safety root cause beyond the malformed tag.
Description
Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with complete impact and a very high EPSS score, but the flaw is in a long-deprecated product and no KEV listing is present.
What it is
Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, mishandle a modified DeclareFunction2 Actionscript tag in an SWF file, preventing an object from being instantiated properly. A remote attacker can supply a crafted SWF that triggers memory corruption and arbitrary code execution in the context of the player. The record does not specify the exact memory-safety root cause beyond the malformed tag.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the user running Flash Player, which on typical systems means full compromise of that user's session. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.
Attack surface
Reached over the network by delivering a malicious SWF file, typically via a web page or embedded content that the victim loads in Flash Player. No authentication is required (Au:N), but the CVSS vector shows medium access complexity (AC:M), implying some condition such as a specific player version or crafted tag layout must be met; user interaction is not stated in the record.
Exploitation
Not listed in CISA KEV, but EPSS is 0.5977 (99.1st percentile), indicating a high modeled likelihood of exploitation activity. A SecurityFocus BID reference carries an Exploit tag, so public exploit information exists, though the record does not describe a weaponized exploit.
What to do
- Upgrade Flash Player to a version later than 9.0.115.0 / 8.0.39.0 per Adobe bulletin APSB08-11, or remove Flash Player where it is no longer needed.
- Apply the vendor patches referenced by the Red Hat, openSUSE, Gentoo, Sun and Apple advisories for bundled or platform Flash components.
- Disable or restrict Flash content in browsers and email clients, and block untrusted SWF files at the gateway where feasible.
- Enforce least privilege and browser sandboxing so a Flash compromise does not yield broader host control.
Detection
- Hunt for Flash Player processes spawning unexpected child processes or making anomalous network connections after loading SWF content.
- Monitor for crashes or memory-corruption events in Flash Player (browser plugin crash reports) tied to SWF loads from untrusted origins.
- Inspect proxy and web logs for SWF files delivered from unusual or newly seen hosts, especially where Flash is still installed.
- Use the OVAL definition referenced in the record to check endpoint Flash Player versions against the vulnerable range.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-6019 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-6019), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.