CVE-2011-0609
published 2011-03-15CVE-2011-0609: Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR…
PriorityP184high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-06-22
Exploited in the wild
EPSS
66.82%
99.2th percentile
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | — | — |
| adobe | acrobat | — | — |
| adobe | acrobat | 9.0 – 9.4.2 | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | — | — |
| adobe | acrobat_reader | 9.0 – 9.4.2 | — |
| adobe | air | <= 2.5.1 | — |
| adobe | flash_player | <= 10.2.154.13 | — |
| adobe | flash_player | <= 10.1.106.16 | — |
| chrome | < 10.0.648.134 | 10.0.648.134 | |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise | — | — |
| suse | linux_enterprise | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect .swf files embedded within Excel (.xls) spreadsheets delivered as email attachments — the primary in-the-wild delivery vector for this CVE. ↗
- →The exploit uses JavaScript heap spraying with a NOP sled value of 0x04040404 (repeated 4-byte pattern) to control uninitialized memory prior to execution; this pattern can be used as a memory/network signature. ↗
- →The exploit serves a trigger SWF with Content-Type 'application/x-shockwave-flash' and uses HTTP compression (gzip) and chunked transfer encoding — monitor for gzip+chunked SWF delivery to browsers. ↗
- →The Metasploit module auto-migrates the payload process post-exploitation; look for Flash Player or browser child processes spawning unexpected process migrations shortly after SWF load. ↗
- →The exploit targets AVM2 bytecode verification failure leading to uninitialized memory execution; AVM2/ActionScript3 bytecode anomalies in SWF files (malformed bytecode streams) are a key detection surface. ↗
- →The exploit is confirmed to work against IE6, IE7, and Firefox 3.6; DEP causes the exploit to fail — absence of DEP on the target system increases risk. Monitor Flash execution within these browser processes. ↗
- →The JS heap spray in the exploit uses unescape() with shellcode and a repeated NOP sled in a loop — detect large unescape() calls combined with SWF object embedding in HTML pages. ↗
- ·Adobe Reader X Protected Mode mitigations prevent this exploit from executing in that context; detections targeting Reader X may yield fewer hits. ↗
- ·This flaw does not affect Adobe Acrobat Reader 9.x for UNIX, limiting the Linux/Unix Reader attack surface. ↗
- ·DEP (Data Execution Prevention) causes the exploit to fail; systems with DEP enabled are not reliably exploitable via this module. ↗
- ·Payload space is limited to 1000 bytes with null bytes as bad characters; staged/large payloads may not function correctly. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g9g3-3gv9-454q: Unspecified vulnerability in Adobe Flash Player 10
ghsa_unreviewed·2022-05-14
CVE-2011-0609 [HIGH] GHSA-g9g3-3gv9-454q: Unspecified vulnerability in Adobe Flash Player 10
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.
VulnCheck
Adobe Flash Player Unspecified Vulnerability
vulncheck·2011·CVSS 7.8
CVE-2011-0609 [HIGH] Adobe Flash Player Unspecified Vulnerability
Adobe Flash Player Unspecified Vulnerability
Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
Affected: Adobe Flash Player
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Exploitation References: https://www.cve.org/CVERecord?id=CVE-2011-0609; https://www.trendmicro.de/cloud-content/us/pdfs/security-intelligence/white-papers/wp_ixeshe.pdf; http://www.cs.cornell.edu/courses/cs6410/2012fa/slides/Symantec_ElderwoodProject_2012.pdf; https://dl.acm.org/doi/pdf/10.1145/3465481.3465758; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-06-22
CISA
Adobe Flash Player Unspecified Vulnerability
cisa·2022-06-08·CVSS 7.8
CVE-2011-0609 [HIGH] Adobe Flash Player Unspecified Vulnerability
Vulnerability: Adobe Flash Player Unspecified Vulnerability
Affected: Adobe Flash Player
Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2011-0609
Remediation Due Date: 2022-06-22
Red Hat
flash-plugin: crash and potential arbitrary code execution (APSB11-05)
vendor_redhat·2011-03-14·CVSS 7.8
CVE-2011-0609 [HIGH] flash-plugin: crash and potential arbitrary code execution (APSB11-05)
flash-plugin: crash and potential arbitrary code execution (APSB11-05)
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.
No detection rules found.
Exploit-DB
Adobe Flash Player - AVM Bytecode Verification (Metasploit)
exploitdb·2011-03-23
CVE-2011-0609 Adobe Flash Player - AVM Bytecode Verification (Metasploit)
Adobe Flash Player - AVM Bytecode Verification (Metasploit)
---
##
# $Id: adobe_flashplayer_avm.rb 12091 2011-03-23 04:41:48Z bannedit $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Adobe Flash Player AVM Bytecode Verification',
'Description' => %q{
This module exploits a vulnerability in AVM2 action script virtual machine used
in Adobe Flash Player versions 9.0 through 10. The AVM fails to properly verify
bytecode streams prior to executing it. This can cause uninitialized memory to be
executed.
Utilizing heap spraying techniques to co
Metasploit
Adobe Flash Player AVM Bytecode Verification Vulnerability
metasploit
Adobe Flash Player AVM Bytecode Verification Vulnerability
Adobe Flash Player AVM Bytecode Verification Vulnerability
This module exploits a vulnerability in Adobe Flash Player versions 10.2.152.33 and earlier. This issue is caused by a failure in the ActionScript3 AVM2 verification logic. This results in unsafe JIT(Just-In-Time) code being executed. This is the same vulnerability that was used for the RSA attack in March 2011. Specifically, this issue results in uninitialized memory being referenced and later executed. Taking advantage of this issue relies on heap spraying and controlling the uninitialized memory. Currently this exploit works for IE6, IE7, and Firefox 3.6 and likely several other browsers. DEP does catch the exploit and causes it to fail. Due to the nature of the uninitialized memory its fairly difficult to get around this restr
arXiv
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
arxiv_fulltext·2025-02-12
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Almuthanna Alageel
and
Sergio Maffeis
Department of Computing
Imperial College London
London, United Kingdom
plain
plain
## Abstract
The scarcity of data and the high complexity of Advanced Persistent Threats (APTs) attacks have created challenges in comprehending their behavior and hindered the exploration of effective detection techniques.
To create an effective APT detection strategy, it is important to examine the Tactics, Techniques, and Procedures (TTPs) that have been reported by the industry. These TTPs can be difficult to classify as either malicious or legitimate. When developing an approach for the next generation of network intrusion detection systems (NIDS), it is necessary to
Securelist
Investigation Report for the September 2014 Equation malware detection incident in the US
blogs_securelist·2017-11-16
Investigation Report for the September 2014 Equation malware detection incident in the US
Authors
- Kaspersky
## Background
In early October, a story was published by the Wall Street Journal alleging Kaspersky Lab software was used to siphon classified data from an NSA employee’s home computer system. Given that Kaspersky Lab has been at the forefront of fighting cyberespionage and cybercriminal activities on the Internet for over 20 years now, these allegations were treated very seriously. To assist any independent investigators and all the people who have been asking us questions whether those allegations were true, we decided to conduct an internal investigation to attempt to answer a few questions we had related to the article and some others that followed it:
1. Was our software used outside of its intended functionality to pull classified information from a person’s c
Securelist
Investigation Report for the September 2014 Equation malware detection incident in the US
blogs_securelist·2017-11-16
Investigation Report for the September 2014 Equation malware detection incident in the US
Authors
Kaspersky
## Background
In early October, a story was published by the Wall Street Journal alleging Kaspersky Lab software was used to siphon classified data from an NSA employee’s home computer system. Given that Kaspersky Lab has been at the forefront of fighting cyberespionage and cybercriminal activities on the Internet for over 20 years now, these allegations were treated very seriously. To assist any independent investigators and all the people who have been asking us questions whether those allegations were true, we decided to conduct an internal investigation to attempt to answer a few questions we had related to the article and some others that followed it:
Was our software used outside of its intended functionality to pull classified information from a person’s comput
Threat Intel
APT12 (APT12, IXESHE, DynCalc)
threat_intel·CVSS 8.8
[HIGH] APT12 (APT12, IXESHE, DynCalc)
# Threat Actor Profile: APT12
ATT&CK ID: G0005
Also known as: APT12, IXESHE, DynCalc, Numbered Panda, DNSCALC
Suspected origin: China
## Overview
APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.(Citation: Meyers Numbered Panda)
## Techniques (TTPs)
### Initial Access
- T1566.001 Spearphishing Attachment
Usage: APT12 has sent emails with malicious Microsoft Office documents and PDFs attached.(Citation: Moran 2014)(Citation: Trend Micro IXESHE 2012)
### Execution
- T1204.002 Malicious File
Usage: APT12 has attempted to get victims to open malicious Microsoft Word and PDF attachment sent via spearphishing.(Citation: Moran 2014)(Citation: Trend Mi
Bugzilla
CVE-2011-0609 flash-plugin: crash and potential arbitrary code execution (APSB11-05)
bugzilla·2011-03-14·CVSS 7.8
CVE-2011-0609 [HIGH] CVE-2011-0609 flash-plugin: crash and potential arbitrary code execution (APSB11-05)
CVE-2011-0609 flash-plugin: crash and potential arbitrary code execution (APSB11-05)
Adobe has released APSA11-01 [1] to warn of a new critical vulnerability in Adobe Flash Player 10.x. The expected release is the week of March 21st. The vulnerability is described as:
This vulnerability (CVE-2011-0609) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a Flash (.swf) file embedded in a Microsoft Excel (.xls) file delivered as an email attachment. Adobe is not currently aware of attacks targeting Adobe Reader and Acrobat. Adobe Reader X Protected Mode mitigations would prevent an exploit of this kind from executing.
This flaw does not affect Adobe Ac
http://blogs.adobe.com/asset/2011/03/background-on-apsa11-01-patch-schedule.htmlhttp://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates_15.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://secunia.com/advisories/43751http://secunia.com/advisories/43757http://secunia.com/advisories/43772http://secunia.com/advisories/43856http://securityreason.com/securityalert/8152http://www.adobe.com/support/security/advisories/apsa11-01.htmlhttp://www.adobe.com/support/security/bulletins/apsb11-06.htmlhttp://www.kb.cert.org/vuls/id/192052http://www.redhat.com/support/errata/RHSA-2011-0372.htmlhttp://www.securityfocus.com/bid/46860http://www.securitytracker.com/id?1025210http://www.securitytracker.com/id?1025211http://www.securitytracker.com/id?1025238http://www.vupen.com/english/advisories/2011/0655http://www.vupen.com/english/advisories/2011/0656http://www.vupen.com/english/advisories/2011/0688http://www.vupen.com/english/advisories/2011/0732https://exchange.xforce.ibmcloud.com/vulnerabilities/66078https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14147http://blogs.adobe.com/asset/2011/03/background-on-apsa11-01-patch-schedule.htmlhttp://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates_15.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://secunia.com/advisories/43751http://secunia.com/advisories/43757http://secunia.com/advisories/43772http://secunia.com/advisories/43856http://securityreason.com/securityalert/8152http://www.adobe.com/support/security/advisories/apsa11-01.htmlhttp://www.adobe.com/support/security/bulletins/apsb11-06.htmlhttp://www.kb.cert.org/vuls/id/192052http://www.redhat.com/support/errata/RHSA-2011-0372.htmlhttp://www.securityfocus.com/bid/46860http://www.securitytracker.com/id?1025210http://www.securitytracker.com/id?1025211http://www.securitytracker.com/id?1025238http://www.vupen.com/english/advisories/2011/0655http://www.vupen.com/english/advisories/2011/0656http://www.vupen.com/english/advisories/2011/0688http://www.vupen.com/english/advisories/2011/0732https://exchange.xforce.ibmcloud.com/vulnerabilities/66078https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14147https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-0609
2011-03-15
Published
2022-06-08
Added to CISA KEV
Exploited in the wild