Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and before 11.1.115.8 on Android 4.x allows remote attackers to execute arbitrary code via a crafted file, related to an "object confusion vulnerability," as exploited in the wild in May 2012.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Apsb12 09 | — | Upgrade to Adobe Flash Player version 11.2.202.235 for LinuxUpgrade to Adobe Flash Player version 11.2.202.235 for Mac OS XUpgrade to Adobe Flash Player version 11.2.202.235 for Windows | Jun 20, 2012 | May 4, 2012 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | May 4, 2012 |
| Suse | — | Upgrade flash-playerUpgrade flash-player-gnomeUpgrade flash-player-kde4 | Feb 17, 2015 | May 4, 2012 |
| Ubuntu | — | Upgrade adobe-flashpluginUpgrade flashplugin-nonfree | Nov 19, 2024 | May 4, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub