Description
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.
CVSS Metrics
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Vector
- local
- Complexity
- low
- Privileges
- none
- User Action
- required
- Scope
- unchanged
- Confidentiality
- high
- Integrity
- high
- Availability
- high
- Weaknesses
- NVD-CWE-noinfo
Metadata
- Primary Vendor
- ADOBE
- Published
- 3/15/2011
- Last Modified
- 10/22/2025
- Source
- NIST NVD
- Note: Verify all details with official vendor sources before applying patches.
Affected Products
adobe : flash_playeradobe : flash_playeradobe : acrobatadobe : acrobatadobe : acrobatadobe : acrobat_readeradobe : acrobat_readeradobe : acrobat_readeradobe : airopensuse : opensuseopensuse : opensuseopensuse : opensusesuse : linux_enterprisesuse : linux_enterprisegoogle : chrome
AI-Powered Remediation
Generate remediation guidance or a C-suite brief for this vulnerability.