Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted SWF content, as exploited in the wild in August 2012 with SWF content in a Word document.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Apsb12 18 | — | Upgrade to Adobe Flash Player version 11.2.202.238 for LinuxUpgrade to Adobe Flash Player version 11.3.300.271 for Mac OS XUpgrade to Adobe Flash Player version 11.3.300.271 for Windows | Aug 21, 2012 | Aug 15, 2012 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Aug 15, 2012 |
| Hpsim | — | Upgrade to the latest version of HP Systems Insight Manager | Oct 13, 2015 | Aug 15, 2012 |
| Suse | — | Upgrade flash-player-kde4Upgrade flash-player-gnomeUpgrade flash-player | Feb 17, 2015 | Aug 15, 2012 |
| Ubuntu | — | Upgrade adobe-flashpluginUpgrade flashplugin-nonfree | Nov 19, 2024 | Aug 15, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub