An issue has been reported in Flash, which could allow for a remote user to access known local files. The undocumented FSCommand 'exec' action is used to execute external applications. In order to utilize this command, the absolute path to the requested application must be argumented. As a result an attacker could compose a malicious swf file and access a known file residing on the user's system.
Macromedia Flash Undocumented Action File Access Vulnerability