CVE-2010-3654

High PUBLISHED

Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll...

Adobe · Flash Player

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
9.3 High

At a Glance

Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content, as exploited in the wild in October 2010.

linux metasploit macos android windows
CVE Published
Oct 29, 2010
Exploitation Reported
Oct 29, 2010
CVSS
9.3 High
EPSS
Remote Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • GLSA-201101-09 security.gentoo.org · Vendor Advisory http://security.gentoo.org/glsa/glsa-201101-09.xml
  • APPLE-SA-2010-11-10-1 lists.apple.com · Vendor Advisory http://lists.apple.com/archives/security-announce/2010//Nov/msg00000....
  • GLSA-201101-08 security.gentoo.org · Vendor Advisory http://security.gentoo.org/glsa/glsa-201101-08.xml
  • RHSA-2010:0834 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0834.html
  • SUSE-SA:2010:055 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00002...
Show 32 more references
  • RHSA-2010:0934 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0934.html
  • TLSA-2011-2 turbolinux.co.jp · Vendor Advisory http://www.turbolinux.co.jp/security/2011/TLSA-2011-2j.txt
  • SUSE-SA:2010:058 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00001...
  • RHSA-2010:0867 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0867.html
  • RHSA-2010:0829 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0829.html
  • 42183 secunia.com · Third-Party Advisory http://secunia.com/advisories/42183
  • 42030 secunia.com · Third-Party Advisory http://secunia.com/advisories/42030
  • 43025 secunia.com · Third-Party Advisory http://secunia.com/advisories/43025
  • 43026 secunia.com · Third-Party Advisory http://secunia.com/advisories/43026
  • 41917 secunia.com · Third-Party Advisory http://secunia.com/advisories/41917
  • 42926 secunia.com · Third-Party Advisory http://secunia.com/advisories/42926
  • 42401 secunia.com · Third-Party Advisory http://secunia.com/advisories/42401
  • VU#298081 kb.cert.org · Third-Party Advisory http://www.kb.cert.org/vuls/id/298081
  • 8210 securityreason.com · Third-Party Advisory http://securityreason.com/securityalert/8210
  • ADV-2011-0192 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2011/0192
  • ADV-2011-0191 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2011/0191
  • ADV-2011-0344 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2011/0344
  • ADV-2010-2918 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/2918
  • ADV-2010-3111 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/3111
  • 1024660 securitytracker.com · VDB Entry http://www.securitytracker.com/id?1024660
  • ADV-2010-2903 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/2903
  • ADV-2011-0173 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2011/0173
  • 1024659 securitytracker.com · VDB Entry http://www.securitytracker.com/id?1024659
  • 44504 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/44504
  • ADV-2010-2906 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/2906
  • oval:org.mitre.oval:def:13294 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...
  • contagiodump.blogspot.com/2010/10/potential-new-adobe-flash-player-zer... contagiodump.blogspot.com · CVE Record http://contagiodump.blogspot.com/2010/10/potential-new-adobe-flash-pl...
  • support.apple.com/kb/HT4435 support.apple.com · CVE Record http://support.apple.com/kb/HT4435
  • blogs.sun.com/security/entry/multiple_vulnerabilities_in_a... blogs.sun.com · CVE Record http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_adobe...
  • adobe.com/support/security/bulletins/apsb10-26.html adobe.com · CVE Record http://www.adobe.com/support/security/bulletins/apsb10-26.html
  • adobe.com/support/security/advisories/apsa10-05.html adobe.com · CVE Record http://www.adobe.com/support/security/advisories/apsa10-05.html
  • adobe.com/support/security/bulletins/apsb10-28.html adobe.com · CVE Record http://www.adobe.com/support/security/bulletins/apsb10-28.html

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.