Back
CVE-2011-0609
HIGH
CISA KEV
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.
Published: Mar 15, 2011
Modified: Apr 21, 2026
NVD-CWE-noinfo
CVSS Metrics
CVSSv3
Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
REQUIRED
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products (15)
| Vendor | Product | Version |
|---|---|---|
| adobe | flash_player | * |
| adobe | flash_player | * |
| adobe | acrobat | * ≥ 9.0 |
| adobe | acrobat | 10.0 |
| adobe | acrobat | 10.0.1 |
| adobe | acrobat_reader | * ≥ 9.0 |
| adobe | acrobat_reader | 10.0 |
| adobe | acrobat_reader | 10.0.1 |
| adobe | air | * |
| opensuse | opensuse | 11.2 |
| opensuse | opensuse | 11.3 |
| opensuse | opensuse | 11.4 |
| suse | linux_enterprise | 10.0 |
| suse | linux_enterprise | 11.0 |
| chrome | * < 10.0.648.134 |
References (45)
- http://blogs.adobe.com/asset/2011/03/background-on-apsa11-01-patch-schedule.html Broken Link
- http://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates_15.html Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html Mailing List, Third Party Advisory
- http://secunia.com/advisories/43751 Broken Link
- http://secunia.com/advisories/43757 Broken Link
- http://secunia.com/advisories/43772 Broken Link
- http://secunia.com/advisories/43856 Broken Link
- http://securityreason.com/securityalert/8152 Broken Link
- http://www.adobe.com/support/security/advisories/apsa11-01.html Vendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb11-06.html Not Applicable
- http://www.kb.cert.org/vuls/id/192052 Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2011-0372.html Broken Link
- http://www.securityfocus.com/bid/46860 Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1025210 Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1025211 Broken Link, Third Party Advisory, VDB Entry
Risk Scores
CVSS Score
7.8 / 10
EPSS Score
92.08%
Top 0% most likely to be exploited
Threat Score
88.8 / 100
CISA Known Exploited
Date Added:
2022-06-08
Due Date:
2022-06-22
Required Action:
The impacted product is end-of-life and should be disconnected if still in use.
Data Sources
NVD
CISA KEV
EPSS