ZeroHour

CVE-2012-5054

KEVmass

Remote Code Execution via Integer Overflow in Adobe Flash Player

CISA: Adobe Flash Player Integer Overflow Vulnerability

CVSS
EPSS
21%p97
Published
KEV added
AI analysis

Adobe Flash Player contains an integer overflow weakness (CWE-189 category) that a remote attacker can trigger by having the player process malformed arguments, typically via malicious Flash content. Successful exploitation allows the attacker to execute arbitrary code in the context of the Flash Player process, i.e., potentially with the privileges of the user's account. Anyone running Adobe Flash Player is affected; because Flash is end-of-life (support ended December 31, 2020), current exposure is limited to leftover or unmigrated installations on legacy systems and applications. CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2022-06-08, indicating exploitation in the wild, with ransomware association unknown; EPSS estimates a 21.2% probability of exploitation in the next 30 days (97th percentile), and no public proof-of-concept is known.

What to do: Uninstall or disable Adobe Flash Player on all systems, per CISA's required action for this end-of-life product; check for residual browser plugins, standalone Flash projectors, and embedded/OEM copies of Flash that lack Adobe's automatic content blocking. Where legacy Flash use is unavoidable, upgrade to the last available release, isolate those hosts from untrusted content, and plan removal, since no new patches will be issued.

Affected
Adobe Flash Player
Estimated exposure
masstens of millions of legacy installations remain worldwide (Flash historically shipped on ~99% of PCs, ~1 billion+ devices) — Estimated from Adobe's historical near-universal install base of over a billion devices, discounted sharply for the post-end-of-life decline since Adobe blocked Flash content in January 2021, leaving mainly unmigrated enterprise and legacy…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments.

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Flash Player
Weakness
CWE-189

In the news