KEVIntel
9.3
CVSS
High

CVE-2010-3654

PUBLISHED

Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll...

Not yet in CISA KEV

Exploited in the wild PoC available Remote
Vendor
Adobe
Product
Flash Player
Published
Oct 29, 2010
EPSS

Automate This Intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content, as exploited in the wild in October 2010.

windows linux macos android metasploit

CVSS Scores

CVSS v2.0 9.3 High

AV:N/AC:M/Au:N/C:C/I:C/A:C

Exploitation Status

Exploited in the wild

Recorded 2010-10-29 18:00:00 UTC · CVE

Proof of concept available

Recorded 2025-04-28 15:02:44 UTC

References

Known Exploited Vulnerability Sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE First 2010-10-29 18:00 UTC

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

adobe_flashplayer_button

metasploit · Created Unknown

Metasploit module for CVE-2010-3654

Timeline

  • Detected by Metasploit

  • Proof of Concept Exploit Available

  • Added to KEVIntel

  • CVE Published to Public

  • CVE ID Reserved