SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2012-5054

Adobe Flash Player Integer Overflow Vulnerability

KEVHIGH 8.8EPSS 21.2%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
21.19% probability · 97th percentile
CISA KEV
Listed 8 June 2022 · due 22 June 2022
Weakness
CWE-190
Affected
adobe/flash player
Source
psirt@adobe.com

CISA notes

The impacted product is end-of-life and should be disconnected if still in use. https://nvd.nist.gov/vuln/detail/CVE-2012-5054

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.