Untrusted search path vulnerability in the installer in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows local users to gain privileges via a Trojan horse executable file in an unspecified directory.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Air | — | — | Jun 19, 2012 | Jun 8, 2012 |
| Adobe Apsb12 14 | — | Upgrade to Adobe Flash Player version 10.3.183.20 for LinuxUpgrade to Adobe Flash Player version 11.3.300.257 for Mac OS XUpgrade to Adobe Flash Player version 11.3.300.257 for WindowsUpgrade to Adobe Flash Player version 10.3.183.20 for WindowsUpgrade to Adobe Flash Player version 10.3.183.20 for Mac OS X | Jun 29, 2012 | Jun 8, 2012 |
| Freebsd | — | Upgrade linux-f10-flashplugin | Dec 10, 2025 | Nov 2, 2012 |
| Gentoo Linux | — | Upgrade www-plugins/adobe-flash. | Oct 30, 2017 | Jun 8, 2012 |
| Suse | — | Upgrade flash-player-gnomeUpgrade flash-player | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade flashplugin-nonfreeUpgrade adobe-flashplugin | Nov 19, 2024 | Jun 9, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub