Junglewise Threat Intelligence

CVE-2010-1297: Adobe Flash Player Memory Corruption Vulnerability

CVE-2010-1297 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2022-06-08

Technologies: Adobe Acrobat, Adobe Flash Player, Adobe AIR, Adobe Reader. Vendors: Adobe.

Executive brief

Adobe Flash Player, AIR, Reader, and Acrobat contain a memory corruption vulnerability in the authplay.dll component. The flaw is triggered by the ActionScript Virtual Machine 2 (AVM2) newfunction instruction when processing crafted SWF content, allowing for remote code execution or denial of service.

Affected products

  • Adobe Flash Player before 9.0.277.0, 10.x before 10.1.53.64
  • Adobe AIR before 2.0.2.12610
  • Adobe Reader 9.x before 9.3.3, 8.x before 8.2.3
  • Adobe Acrobat 9.x before 9.3.3, 8.x before 8.2.3

Timeline

  • 2010-06-04: exploited: Exploited in the wild in June 2010.
  • 2022-06-08: disclosed: NVD publication date.

Related threats