ZeroHour

CVE-2012-1535

KEVmass

Arbitrary Code Execution via Crafted SWF Content in Adobe Flash Player (EOL)

CISA: Adobe Flash Player Arbitrary Code Execution Vulnerability

CVSS
EPSS
70%p99
Published
KEV added
AI analysis

CVE-2012-1535 is an unspecified vulnerability in Adobe Flash Player that allows remote attackers to execute arbitrary code or cause a denial of service when the player processes specially crafted SWF content. It is typically triggered when a user opens a web page, advertisement, or document that embeds the hostile SWF file. A successful exploit gives the attacker code execution in the context of the user running Flash, enabling full system compromise; a failed or partial exploit can crash the player. Anyone still running unpatched Adobe Flash Player is affected, and because the product is end-of-life and no longer receives security updates, CISA's required action is to disconnect or remove it if still in use. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-03-03 (ransomware use unknown), and EPSS assigns a 70.4% probability of exploitation within 30 days, though no public proof-of-concept is known.

What to do: Audit the environment for any remaining Flash Player usage — browser plugins, standalone projectors, and SWF content embedded in legacy intranet applications, kiosks, and e-learning tools — and remove or disconnect it, per CISA's required action for this EOL product. If Flash content must be retained, isolate it from untrusted sources (block .swf at the gateway, do not load remote SWF) and plan migration to modern alternatives. No vendor patch will be issued, so remediation means removal, not upgrading.

Affected
Adobe Flash Player
Estimated exposure
mass≈1M+ residual installations worldwide (Flash was historically installed on virtually every desktop; EOL since December 2020) — Flash Player had cumulative installs in the billions at peak, and even a small residual population of legacy enterprise apps, kiosks, embedded systems, and offline machines that never updated before end-of-life plausibly exceeds a million…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content.

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Flash Player

In the news