Junglewise Threat Intelligence

CVE-2012-5054: Adobe Flash Player Integer Overflow Vulnerability

CVE-2012-5054 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-06-08

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

An integer overflow vulnerability exists in the copyRawDataTo method of the Matrix3D class in Adobe Flash Player. Remote attackers can exploit this flaw via malformed arguments to execute arbitrary code on the target system.

Affected products

  • Adobe Flash Player before 11.4.402.265

Timeline

  • 2012-08-21: advisory: Adobe released security bulletin APSB12-19 addressing this issue.
  • 2022-06-08: kev added: CISA added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.
  • 2022-06-08: disclosed: NVD publication date.
  • 2012-09-13: other: Public exploit published on Packet Storm Security.

Related threats