Executive brief
An unspecified vulnerability in Adobe Flash Player and Adobe AIR allows remote attackers to execute arbitrary code or cause a denial of service via crafted Flash content. The flaw can be triggered by a .swf file embedded in an Excel spreadsheet and was actively exploited in the wild.
Affected products
- Adobe Flash Player 10.2.154.13 and earlier (Windows, Mac OS X, Linux, Solaris); 10.1.106.16 and earlier (Android)
- Adobe AIR 2.5.1 and earlier
- Adobe Reader 9.x through 9.4.2, 10.x through 10.0.1
- Adobe Acrobat 9.x through 9.4.2, 10.x through 10.0.1
Timeline
- 2011-03-01: exploited: Exploited in the wild in March 2011.
- 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.