Junglewise Threat Intelligence

CVE-2012-2034: Adobe Flash Player Memory Corruption Vulnerability

CVE-2012-2034 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-03-28

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Flash Player and AIR contain a memory corruption vulnerability that allows for remote code execution or denial-of-service. The flaw is triggered via unspecified vectors and has been observed being exploited in the wild.

Affected products

  • Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x
  • Adobe AIR before 3.3.0.3610

Timeline

  • 2012-06-08: advisory: Adobe Security Bulletin APSB12-14 published
  • 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-28: disclosed: NVD publication date

Related threats