Vulnerability Intelligence Report
Adobe Flash Player Unspecified Vulnerability
CVE-2011-0609
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:66.82%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| adobe | flash_player | all |
| apple | mac_os_x | all |
| linux | linux_kernel | all |
| microsoft | windows | all |
| oracle | solaris | all |
| android | all | |
| adobe | acrobat | 10.0, 10.0.1 |
| adobe | acrobat_reader | 10.0, 10.0.1 |
| adobe | air | all |
| opensuse | opensuse | 11.2, 11.3, 11.4 |
| suse | linux_enterprise | 10.0, 11.0 |
| chrome | all | |
| apple | macos | all |
| chrome_os | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Adobe Systems Incorporated · Vendor · USA |
| Reserved | 2011-01-20T00:00:00 |
| Published | 2011-03-15T17:00:00 |
| Patch Date | 2011-03-14 |
| Last Updated | 2025-10-22T00:05:49 |
Community Chatter & Buzz