ZeroHour

CVE-2011-0609

KEVmass

Unspecified Remote Code Execution Vulnerability in Adobe Flash Player

CISA: Adobe Flash Player Unspecified Vulnerability

CVSS
EPSS
67%p99
Published
KEV added
AI analysis

Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute arbitrary code or cause a denial-of-service condition. The flaw is triggered remotely, almost certainly via malicious Flash content processed by the player in a browser or standalone runtime, although Adobe did not disclose detailed technical specifics for this CVE. Successful exploitation gives an attacker the ability to run code with the privileges of the user running Flash, or to crash the application. Anyone running affected builds of Flash Player is exposed; at the time of disclosure in 2011 that meant nearly every internet-connected desktop, whereas today it is limited to residual end-of-life installs. The vulnerability is listed in the CISA KEV catalog (added 2022-06-08) and carries a high EPSS score of 66.8% (99th percentile), indicating known exploitation in the wild, though no public proof-of-concept is known.

What to do: Flash Player is end-of-life and no longer receives security updates, so inventory systems for any remaining Flash installs and remove or disable them where possible; CISA's required action is to disconnect impacted products if still in use. For legacy systems that must retain Flash, isolate them from untrusted web content and treat this code execution flaw as actively exploited.

Affected
Adobe Flash Player
Estimated exposure
masson the order of hundreds of millions of installs at the time of disclosure (Flash ran on ~99% of internet-connected PCs in 2011); the number of residual… — Adobe Flash Player was near-universally deployed across browsers in 2011, so the plausibly affected population at disclosure exceeded one million users by several orders of magnitude, while the current remaining EOL install base is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Flash Player

In the news