CVE-2011-0609
KEVmassUnspecified Remote Code Execution Vulnerability in Adobe Flash Player
CISA: Adobe Flash Player Unspecified Vulnerability
Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute arbitrary code or cause a denial-of-service condition. The flaw is triggered remotely, almost certainly via malicious Flash content processed by the player in a browser or standalone runtime, although Adobe did not disclose detailed technical specifics for this CVE. Successful exploitation gives an attacker the ability to run code with the privileges of the user running Flash, or to crash the application. Anyone running affected builds of Flash Player is exposed; at the time of disclosure in 2011 that meant nearly every internet-connected desktop, whereas today it is limited to residual end-of-life installs. The vulnerability is listed in the CISA KEV catalog (added 2022-06-08) and carries a high EPSS score of 66.8% (99th percentile), indicating known exploitation in the wild, though no public proof-of-concept is known.
What to do: Flash Player is end-of-life and no longer receives security updates, so inventory systems for any remaining Flash installs and remove or disable them where possible; CISA's required action is to disconnect impacted products if still in use. For legacy systems that must retain Flash, isolate them from untrusted web content and treat this code execution flaw as actively exploited.
| Adobe Flash Player | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
- Affected
- Adobe Flash Player
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- Adobe
- Products
- Flash Player