⚠ Actively exploited
Added to CISA KEV on 2022-06-08. Federal agencies required to patch by 2022-06-22. Required action: The impacted product is end-of-life and should be disconnected if still in use..

CVE-2012-0754Out-of-bounds Write in Adobe Flash Player

Severity
8.1HIGHNVD
EPSS
91.5%
top 0.32%
CISA KEV
KEV
Added 2022-06-08
Due 2022-06-22
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedFeb 16
KEV addedJun 8
KEV dueJun 22
CISA Required Action: The impacted product is end-of-life and should be disconnected if still in use.

Description

Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages1 packages

NVDadobe/flash_player11.011.1.102.62+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p5xj-3764-5mhh: Adobe Flash Player before 102022-05-14
VulnCheck
Adobe Flash Player Memory Corruption Vulnerability2012

💥Exploits & PoCs

2
Exploit-DB
Adobe Flash Player - '.mp4 cprt' Remote Overflow (Metasploit)2012-03-08
Metasploit
Adobe Flash Player MP4 'cprt' Overflow

🔍Detection Rules

1
Suricata
ET MALWARE Yayih.A Checkin2012-03-09

📋Vendor Advisories

2
CISA
Adobe Flash Player Memory Corruption Vulnerability2022-06-08
Red Hat
flash-plugin: multiple code execution flaws (APSB12-03)2012-02-15

🕵️Threat Intelligence

2
Securelist
Investigation Report for the September 2014 Equation malware detection incident in the US2017-11-16
Securelist
Investigation Report for the September 2014 Equation malware detection incident in the US2017-11-16

💬Community

1
Bugzilla
CVE-2012-0752 CVE-2012-0753 CVE-2012-0754 CVE-2012-0755 CVE-2012-0756 flash-plugin: multiple code execution flaws (APSB12-03)2012-02-16