CVE-2010-1297 KEV EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 82.2% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-22.
Description
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 82.24% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-787 |
| On CISA KEV | yes — remediate by 2022-06-22 |
| Public exploit | yes |
| Published | 2010-06-08 |
| Last modified | 2026-06-16 |
CISA KEV
| Name | Adobe Flash Player Memory Corruption Vulnerability |
|---|---|
| Added | 2022-06-08 |
| Due | 2022-06-22 |
| Vendor / product | Adobe / Flash Player |
| Ransomware use | none reported |
Affected (7)
| Vendor | Product |
|---|---|
| adobe | acrobat |
| adobe | air |
| adobe | flash player |
| apple | mac os x |
| microsoft | windows |
| opensuse | opensuse |
| suse | linux enterprise |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Adobe Flash Player - 'newfunction' Invalid Pointer Use (Metasploit) (2) | 2010-09-25 |
| exploit-db | Adobe Flash Player - 'newfunction' Invalid Pointer Use (Metasploit) (1) | 2010-09-20 |
| exploit-db | Adobe Acrobat Reader and Flash Player - 'newclass' Invalid Pointer | 2010-09-01 |
| exploit-db | Adobe Flash / Reader - Live Malware | 2010-06-09 |
References
- http://blog.zynamics.com/2010/06/09/analyzing-the-currently-exploited-0-day-for-adobe-reader-and-adobe-flash/
- http://community.websense.com/blogs/securitylabs/archive/2010/06/09/having-fun-with-adobe-0-day-exploits.aspx
- http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
- http://secunia.com/advisories/40026
- http://secunia.com/advisories/40034
- http://secunia.com/advisories/40144
- http://secunia.com/advisories/40545
- http://secunia.com/advisories/43026
- http://security.gentoo.org/glsa/glsa-201101-09.xml
- http://securitytracker.com/id?1024057
- http://securitytracker.com/id?1024058
- http://securitytracker.com/id?1024085
- http://securitytracker.com/id?1024086
- http://support.apple.com/kb/HT4435
- http://www.adobe.com/support/security/advisories/apsa10-01.html
- http://www.adobe.com/support/security/bulletins/apsb10-14.html
- http://www.adobe.com/support/security/bulletins/apsb10-15.html
→ the Explorer · watch your stack · NVD