CVE-2012-0779

High PUBLISHED

Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and...

Adobe · Flash Player

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
9.3 High

At a Glance

Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and before 11.1.115.8 on Android 4.x allows remote attackers to execute arbitrary code via a crafted file, related to an "object confusion vulnerability," as exploited in the wild in May 2012.

linux android windows macos metasploit
CVE Published
May 04, 2012
Exploitation Reported
May 04, 2012
CVSS
9.3 High
EPSS
Remote Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • openSUSE-SU-2012:0594 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00005...
  • RHSA-2012:0688 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2012-0688.html
  • SUSE-SU-2012:0592 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00004...
  • 49096 secunia.com · Third-Party Advisory http://secunia.com/advisories/49096
  • 49038 secunia.com · Third-Party Advisory http://secunia.com/advisories/49038
Show 5 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.