Untrusted search path vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a file that is processed by Flash Player.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | Mar 21, 2012 | Oct 19, 2010 |
| Adobe Flash Apsb10 26 | — | Upgrade to Adobe Flash Player version 10.1.102.64 for WindowsUpgrade to Adobe Flash Player version 10.1.102.64 for Mac OS XUpgrade to Adobe Flash Player version 9.0.289.0 for Mac OS XUpgrade to Adobe Flash Player version 9.0.289.0 for LinuxUpgrade to Adobe Flash Player version 10.1.102.64 for LinuxUpgrade to Adobe Flash Player version 9.0.289.0 for Windows | Nov 11, 2010 | Oct 19, 2010 |
| Apple Osx Flashplayerplugin | — | Upgrade macOS to the latest versionApply OS X security update 2010-007 | Dec 16, 2011 | Oct 19, 2010 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Oct 19, 2010 |
| Hpsim | — | Upgrade to the latest version of HP Systems Insight Manager | Oct 13, 2015 | Oct 19, 2010 |
| Suse | — | Upgrade flash-player | Feb 17, 2015 | Oct 19, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub