peter bassill · operator
$ cve CVE-2011-0609 JSON

CVE-2011-0609 KEV EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 63.5% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-22.

Description

Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS63.51% — more likely to be exploited than 99% of all CVEs
On CISA KEVyes — remediate by 2022-06-22
Public exploityes
Published2011-03-15
Last modified2026-06-16

CISA KEV

NameAdobe Flash Player Unspecified Vulnerability
Added2022-06-08
Due2022-06-22
Vendor / productAdobe / Flash Player
Ransomware usenone reported

Affected (14)

VendorProduct
adobeacrobat
adobeacrobat reader
adobeair
adobeflash player
applemac os x
applemacos
googleandroid
googlechrome
googlechrome os
linuxlinux kernel
microsoftwindows
opensuseopensuse
oraclesolaris
suselinux enterprise

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD