CVE-2011-0611
KEVmassRemote Code Execution in Adobe Flash Player via Crafted Flash Content
CISA: Adobe Flash Player Remote Code Execution Vulnerability
Adobe Flash Player contains a flaw tracked as CWE-843 that allows remote attackers to execute arbitrary code or crash the application (denial of service) by inducing it to load specially crafted Flash content. Exploitation requires only that a victim's Flash runtime process a malicious SWF file — for example embedded in a document or served by a website — with no authentication involved; related reporting from this era describes waterhole attacks in which compromised websites served Flash exploits to targeted users. A successful attack yields code execution with the privileges of the user running Flash, which for browser-plugin deployments typically means the logged-in desktop user. Anyone running affected Adobe Flash Player is affected; CISA's listing does not enumerate specific vulnerable versions, and the product line is end-of-life. Exploitation is confirmed: the flaw was added to CISA's KEV catalog on 2022-03-03, EPSS assigns a 99.4% 30-day exploitation probability (100th percentile), and no public proof-of-concept is known.
What to do: Because Flash Player is end-of-life and receives no security updates, remove or uninstall it entirely — including browser plugins, standalone runtimes, and any embedded copies — which is also CISA's required action for impacted systems. If removal must be deferred, disconnect affected systems or block untrusted Flash content and audit logs for exploitation, given the confirmed in-the-wild status and ~99% exploitation probability; whether ransomware operators have used this flaw is unknown.
| Adobe Flash Player | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content.
- Affected
- Adobe Flash Player
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- Adobe
- Products
- Flash Player
- Weakness
- CWE-843
In the news7 stories
Tracking Elirks Variants in Japan: Similarities to Previous Attacks
Unit 42 links new Elirks backdoor variants attacking Japanese organizations to 2012 Taiwan attacks, delivered via spear-phishing PDFs exploiting Adobe Flash CVE-2011-0611.
Unit 42 analyzed new Elirks backdoor variants found in an attack on a Japanese business, noting strong similarities to 2012 attacks on Taiwanese ministries. The backdoor retrieves its C2 address from attacker-created accounts on Japanese blog and SNS services. Recent deliveries used an airline e-ticket lure named "E-TKT" with a PDF exploiting Adobe Flash CVE-2011-0611. Shared infrastructure and tactics with the Scarlet Mimic campaign suggest possible ongoing cyber espionage across East Asia.