CVE-2011-2110

High PUBLISHED

Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to...

Adobe · Flash Player

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
10.0 High

At a Glance

Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in June 2011.

macos metasploit android windows linux
CVE Published
Jun 16, 2011
Exploitation Reported
Jun 16, 2011
CVSS
10.0 High
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • RHSA-2011:0869 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2011-0869.html
  • openSUSE-SU-2011:0637 hermes.opensuse.org · Vendor Advisory https://hermes.opensuse.org/messages/8782873
  • 48308 secunia.com · Third-Party Advisory http://secunia.com/advisories/48308
  • 44950 secunia.com · Third-Party Advisory http://secunia.com/advisories/44950
  • 44941 secunia.com · Third-Party Advisory http://secunia.com/advisories/44941
Show 8 more references
  • 44964 secunia.com · Third-Party Advisory http://secunia.com/advisories/44964
  • TA11-166A us-cert.gov · Third-Party Advisory http://www.us-cert.gov/cas/techalerts/TA11-166A.html
  • 44924 secunia.com · Third-Party Advisory http://secunia.com/advisories/44924
  • oval:org.mitre.oval:def:14091 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...
  • oval:org.mitre.oval:def:16252 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...
  • flash-unspec-code-execution(68029) exchange.xforce.ibmcloud.com · VDB Entry https://exchange.xforce.ibmcloud.com/vulnerabilities/68029
  • 1025651 securitytracker.com · VDB Entry http://www.securitytracker.com/id?1025651
  • adobe.com/support/security/bulletins/apsb11-18.html adobe.com · CVE Record http://www.adobe.com/support/security/bulletins/apsb11-18.html

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.