Executive brief
Adobe Flash Player and AIR contain a memory corruption vulnerability that allows for remote code execution or denial-of-service. The flaw is triggered via unspecified vectors and has been observed being exploited in the wild.
Affected products
- Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x
- Adobe AIR before 3.3.0.3610
Timeline
- 2012-06-08: advisory: Adobe Security Bulletin APSB12-14 published
- 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-28: disclosed: NVD publication date