Executive brief
Adobe Flash Player and related products contain a type confusion vulnerability (CWE-843) that allows remote attackers to execute arbitrary code or cause a denial of service. The flaw is triggered via crafted Flash content, such as a Microsoft Office document with an embedded .swf file containing size inconsistencies and malicious ActionScript.
Affected products
- Adobe Flash Player before 10.2.154.27
- Adobe Flash Player for Android 10.2.156.12 and earlier
- Adobe AIR before 2.6.19140
- Adobe Reader 9.x before 9.4.4
- Adobe Reader 10.x 10.0.1 and earlier
- Adobe Acrobat 9.x before 9.4.4
- Adobe Acrobat 10.x before 10.0.3
Timeline
- 2011-04-01: exploited: Exploited in the wild in April 2011.
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.