Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | Upgrade to the latest version of Adobe AIR | Mar 21, 2012 | Mar 15, 2011 |
| Adobe Apsb11 04 | — | Use caution when opening email attachments | Mar 14, 2011 | Mar 14, 2011 |
| Adobe Apsb11 05 | — | Upgrade to Adobe Flash Player version 10.2.153.1 for WindowsUpgrade to Adobe Flash Player version 10.2.153.1 for LinuxUpgrade to Adobe Flash Player version 10.2.153.1 for Mac OS X | Apr 1, 2011 | Mar 21, 2011 |
| Adobe Apsb11 06 | — | — | Apr 1, 2011 | Mar 21, 2011 |
| Adobe Reader Apsb11 06 | — | — | Apr 12, 2012 | Mar 15, 2011 |
| Freebsd | — | Upgrade linux-f10-flashpluginUpgrade linux-f8-flashpluginUpgrade linux-flashplugin | Dec 10, 2025 | Mar 24, 2011 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Mar 15, 2011 |
| Suse | — | Upgrade flash-player | Feb 17, 2015 | Mar 15, 2011 |
| Ubuntu | — | Upgrade flashplugin-nonfreeUpgrade adobe-flashplugin | Nov 19, 2024 | Mar 15, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub