Skip to main content

CVE-2011-0609

7.8
HIGHCVSS v3.1 Base Score
92.08%
HIGH RiskEPSS (100th percentile)
KEV
NVD-CWE-noinfo

Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.

Published: 3/15/2011
Modified: 4/21/2026
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Adobe Flash Player Unspecified Vulnerability

Vendor / Product:

Adobe Flash Player

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

Due Date: 6/22/2022(OVERDUE)
Added to KEV:

6/8/2022

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2011-0609

Vulnerability Summary

CVSS v3 Score

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2 Score

9.3

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

92.08%HIGH Exploitation Risk
100th percentile

This vulnerability has a 92.08% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

CWE Classification

NVD-CWE-noinfo

Related Vulnerabilities