CVE-2010-1297

Confirmed PUBLISHED

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and...

Adobe · Flash Player, AIR, Reader, Acrobat
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.8 High

At a Glance

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.

windows cisa metasploit macos
CVE Published
Jun 08, 2010
Exploitation Reported
Jun 08, 2022
CVSS
7.8 High
EPSS
Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • RHSA-2010:0464 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0464.html
  • GLSA-201101-09 security.gentoo.org · Vendor Advisory http://security.gentoo.org/glsa/glsa-201101-09.xml
  • APPLE-SA-2010-11-10-1 lists.apple.com · Vendor Advisory http://lists.apple.com/archives/security-announce/2010//Nov/msg00000....
  • SUSE-SR:2010:013 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001...
  • TLSA-2010-19 turbolinux.co.jp · Vendor Advisory http://www.turbolinux.co.jp/security/2010/TLSA-2010-19j.txt
Show 38 more references
  • SSRT100179 itrc.hp.com · Vendor Advisory http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751
  • SUSE-SA:2010:024 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00000...
  • RHSA-2010:0470 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0470.html
  • 40545 secunia.com · Third-Party Advisory http://secunia.com/advisories/40545
  • 43026 secunia.com · Third-Party Advisory http://secunia.com/advisories/43026
  • TA10-162A us-cert.gov · Third-Party Advisory http://www.us-cert.gov/cas/techalerts/TA10-162A.html
  • VU#486225 kb.cert.org · Third-Party Advisory http://www.kb.cert.org/vuls/id/486225
  • 40034 secunia.com · Third-Party Advisory http://secunia.com/advisories/40034
  • TA10-159A us-cert.gov · Third-Party Advisory http://www.us-cert.gov/cas/techalerts/TA10-159A.html
  • 40144 secunia.com · Third-Party Advisory http://secunia.com/advisories/40144
  • 40026 secunia.com · Third-Party Advisory http://secunia.com/advisories/40026
  • 13787 exploit-db.com · Exploit http://www.exploit-db.com/exploits/13787
  • ADV-2010-1636 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/1636
  • ADV-2010-1349 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/1349
  • ADV-2011-0192 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2011/0192
  • ADV-2010-1421 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/1421
  • ADV-2010-1793 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/1793
  • ADV-2010-1432 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/1432
  • 40759 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/40759
  • 1024085 securitytracker.com · VDB Entry http://securitytracker.com/id?1024085
  • 1024057 securitytracker.com · VDB Entry http://securitytracker.com/id?1024057
  • 1024086 securitytracker.com · VDB Entry http://securitytracker.com/id?1024086
  • ADV-2010-1434 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/1434
  • 40586 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/40586
  • 1024058 securitytracker.com · VDB Entry http://securitytracker.com/id?1024058
  • ADV-2010-1348 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/1348
  • ADV-2010-1482 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/1482
  • adobe-authplay-code-execution(59137) exchange.xforce.ibmcloud.com · VDB Entry https://exchange.xforce.ibmcloud.com/vulnerabilities/59137
  • ADV-2010-1522 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/1522
  • oval:org.mitre.oval:def:7116 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...
  • 65141 osvdb.org · VDB Entry http://www.osvdb.org/65141
  • ADV-2010-1453 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/1453
  • community.websense.com/blogs/securitylabs/archive/2010/06/09/having... community.websense.com · CVE Record http://community.websense.com/blogs/securitylabs/archive/2010/06/09/h...
  • adobe.com/support/security/bulletins/apsb10-15.html adobe.com · CVE Record http://www.adobe.com/support/security/bulletins/apsb10-15.html
  • support.apple.com/kb/HT4435 support.apple.com · CVE Record http://support.apple.com/kb/HT4435
  • blog.zynamics.com/2010/06/09/analyzing-the-currently-exploited... blog.zynamics.com · CVE Record http://blog.zynamics.com/2010/06/09/analyzing-the-currently-exploited...
  • adobe.com/support/security/advisories/apsa10-01.html adobe.com · CVE Record http://www.adobe.com/support/security/advisories/apsa10-01.html
  • adobe.com/support/security/bulletins/apsb10-14.html adobe.com · CVE Record http://www.adobe.com/support/security/bulletins/apsb10-14.html

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.