CVE-2012-1535
KEVmassArbitrary Code Execution via Crafted SWF Content in Adobe Flash Player (EOL)
CISA: Adobe Flash Player Arbitrary Code Execution Vulnerability
CVE-2012-1535 is an unspecified vulnerability in Adobe Flash Player that allows remote attackers to execute arbitrary code or cause a denial of service when the player processes specially crafted SWF content. It is typically triggered when a user opens a web page, advertisement, or document that embeds the hostile SWF file. A successful exploit gives the attacker code execution in the context of the user running Flash, enabling full system compromise; a failed or partial exploit can crash the player. Anyone still running unpatched Adobe Flash Player is affected, and because the product is end-of-life and no longer receives security updates, CISA's required action is to disconnect or remove it if still in use. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-03-03 (ransomware use unknown), and EPSS assigns a 70.4% probability of exploitation within 30 days, though no public proof-of-concept is known.
What to do: Audit the environment for any remaining Flash Player usage — browser plugins, standalone projectors, and SWF content embedded in legacy intranet applications, kiosks, and e-learning tools — and remove or disconnect it, per CISA's required action for this EOL product. If Flash content must be retained, isolate it from untrusted sources (block .swf at the gateway, do not load remote SWF) and plan migration to modern alternatives. No vendor patch will be issued, so remediation means removal, not upgrading.
| Adobe Flash Player | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content.
- Affected
- Adobe Flash Player
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- Adobe
- Products
- Flash Player