cbcvebase.
CVE-2012-4167
published 2012-08-21

CVE-2012-4167: Integer overflow in Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238…

PriorityP273critical10CVSS 2.0
AVNACLAuNCCICAC
ITWVulnCheck KEV
Exploited in the wild
EPSS
9.23%
94.8th percentile
Integer overflow in Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and before 11.1.115.17 on Android 4.x; Adobe AIR before 3.4.0.2540; and Adobe AIR SDK before 3.4.0.2540 allows attackers to execute arbitrary code via unspecified vectors.

Affected

7 ranges
VendorProductVersion rangeFixed in
adobeair< 3.4.0.25403.4.0.2540
adobeair_sdk< 3.4.0.25403.4.0.2540
adobeflash_player>= 10.3 < 10.3.183.2310.3.183.23
adobeflash_player>= 11.1 < 11.1.111.1611.1.111.16
adobeflash_player>= 11.1 < 11.1.115.1711.1.115.17
adobeflash_player>= 11.2 < 11.2.202.23811.2.202.238
adobeflash_player>= 11.4 < 11.4.402.26511.4.402.265

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is an integer overflow in Adobe Flash Player; detect exploitation attempts by monitoring for Flash Player versions prior to 10.3.183.23 or 11.x prior to 11.4.402.265 (Windows/Mac), 11.2.202.238 (Linux), 11.1.111.16 (Android 2.x/3.x), 11.1.115.17 (Android 4.x), and Adobe AIR prior to 3.4.0.2540
  • ·The attack vector is unspecified in the advisory; no concrete exploit payload, network indicator, or file artifact is publicly documented for this CVE, limiting actionable IOC extraction.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.