Review reviewHigh

CVE-2011-0627

flash player, mac os x

Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content, as possibly exploited in the wild in May 2011 by a Microsoft Office document with an embedded .swf file.

CVSS
8.8
EPSS
5.07%
91.5% percentile
CISA KEV
Not listed
Published
2011.05.14
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability5.07%
Technical severityCVSS 8.8

Vulnerability overview

Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content, as possibly exploited in the wild in May 2011 by a Microsoft Office document with an embedded .swf file.

Affected product and versions

Product
flash player, mac os x
Affected versions
<= 10.2.159.1, 6.0.21.0, 6.0.79, 7.0, 7.0.1, 7.0.14.0, 7.0.19.0, 7.0.24.0, 7.0.25, 7.0.53.0, 7.0.60.0, 7.0.61.0, 7.0.63, 7.0.66.0, 7.0.67.0, 7.0.68.0, 7.0.69.0, 7.0.70.0, 7.0.73.0
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that flash player, mac os x and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE
CWE-20