CVE-2010-1297highunder attackCWE-787

CVE-2010-1297

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.8epss 83%
from disclosure to weapon1 days
Published on NVDJun 8
1st PoC+1d
metasploitJun 4
CISA KEV+4383d
exploitation probability
83%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
5 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
10 products (22 components)
Red Hat Desktop version 4 Extras · Red Hat Enterprise Linux AS version 4 Extras · Red Hat Enterprise Linux Desktop Supplementary (v. 5) · Red Hat Enterprise Linux ES version 4 Extras · Red Hat Enterprise Linux Server Supplementary (v. 5) · and others 5
Action required by CISAfederal deadline: 2022-06-22

The impacted product is end-of-life and should be disconnected if still in use.

In short

Adobe Flash Player and Reader versions before specific dates had a flaw where specially crafted Flash files could crash the program or let attackers run malicious code on your computer.

Technical detail

CWE-787 (out-of-bounds write) in Adobe Flash Player <9.0.277.0 and 10.x <10.1.53.64, Adobe AIR <2.0.2.12610, and Adobe Reader/Acrobat 8.x/9.x affects authplay.dll and AVM2 newfunction instruction. Remote attack via crafted SWF files results in memory corruption, arbitrary code execution, or denial of service; exploited in the wild June 2010.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.