Back

CVE-2011-0609

HIGH CISA KEV

Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.

Published: Mar 15, 2011 Modified: Apr 21, 2026
NVD-CWE-noinfo

CVSS Metrics

CVSSv3
Attack Vector: LOCAL Attack Complexity: LOW Privileges Required: NONE User Interaction: REQUIRED Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products (15)

Vendor Product Version
adobe flash_player *
adobe flash_player *
adobe acrobat * ≥ 9.0
adobe acrobat 10.0
adobe acrobat 10.0.1
adobe acrobat_reader * ≥ 9.0
adobe acrobat_reader 10.0
adobe acrobat_reader 10.0.1
adobe air *
opensuse opensuse 11.2
opensuse opensuse 11.3
opensuse opensuse 11.4
suse linux_enterprise 10.0
suse linux_enterprise 11.0
google chrome * < 10.0.648.134

Risk Scores

CVSS Score 7.8 / 10
EPSS Score 92.08%

Top 0% most likely to be exploited

Threat Score 88.8 / 100

CISA Known Exploited

Date Added: 2022-06-08
Due Date: 2022-06-22
Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

Data Sources

NVD CISA KEV EPSS