Junglewise Threat Intelligence

CVE-2012-1535: Adobe Flash Player Arbitrary Code Execution Vulnerability

CVE-2012-1535 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-03

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

An unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content. The vulnerability was notably exploited in the wild using malicious SWF content embedded within Microsoft Word documents.

Affected products

  • Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X; before 11.2.202.238 on Linux

Timeline

  • 2012-08-14: advisory: Adobe APSB12-18 advisory published
  • 2012-08-01: exploited: Exploited in the wild in August 2012 via Word documents
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats