CVE-2010-1297
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
The impacted product is end-of-life and should be disconnected if still in use.
Adobe Flash Player and Reader versions before specific dates had a flaw where specially crafted Flash files could crash the program or let attackers run malicious code on your computer.
CWE-787 (out-of-bounds write) in Adobe Flash Player <9.0.277.0 and 10.x <10.1.53.64, Adobe AIR <2.0.2.12610, and Adobe Reader/Acrobat 8.x/9.x affects authplay.dll and AVM2 newfunction instruction. Remote attack via crafted SWF files results in memory corruption, arbitrary code execution, or denial of service; exploited in the wild June 2010.
The full analysis of this CVE is available in Portuguese →