Executive brief
Adobe Flash Player, AIR, Reader, and Acrobat contain a memory corruption vulnerability in the authplay.dll component. The flaw is triggered by the ActionScript Virtual Machine 2 (AVM2) newfunction instruction when processing crafted SWF content, allowing for remote code execution or denial of service.
Affected products
- Adobe Flash Player before 9.0.277.0, 10.x before 10.1.53.64
- Adobe AIR before 2.0.2.12610
- Adobe Reader 9.x before 9.3.3, 8.x before 8.2.3
- Adobe Acrobat 9.x before 9.3.3, 8.x before 8.2.3
Timeline
- 2010-06-04: exploited: Exploited in the wild in June 2010.
- 2022-06-08: disclosed: NVD publication date.