CVE-2012-1535
Adobe Flash Player Arbitrary Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted SWF content, as exploited in the wild in August 2012 with SWF content in a Word document.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 70.38% probability · 99th percentile
- CISA KEV
- Listed 3 March 2022 · due 24 March 2022
- Weakness
- CWE-20, CWE-94
- Affected
- adobe/flash player · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · opensuse/opensuse · suse/linux enterprise desktop
- Source
- cve@mitre.org
CISA notes
The impacted product is end-of-life and should be disconnected if still in use. https://nvd.nist.gov/vuln/detail/CVE-2012-1535
References
- http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00010.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00012.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139455789818399&w=2Mailing List
- http://rhn.redhat.com/errata/RHSA-2012-1203.htmlThird Party Advisory
- http://security.gentoo.org/glsa/glsa-201209-01.xmlThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb12-18.htmlNot Applicable, Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00010.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00012.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139455789818399&w=2Mailing List
- http://rhn.redhat.com/errata/RHSA-2012-1203.htmlThird Party Advisory
- http://security.gentoo.org/glsa/glsa-201209-01.xmlThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb12-18.htmlNot Applicable, Patch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-1535US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.