CVE-2011-0609 is an unspecified vulnerability in Adobe Flash Player, Adobe AIR, Adobe Reader, and Acrobat across multiple operating systems. This flaw allows remote attackers to execute arbitrary code or cause a denial of service via crafted Flash content, such as a .swf file embedded in an Excel spreadsheet. With a CVSS score of 7.8 (High), it has a low attack complexity and requires user interaction, but can lead to complete compromise of confidentiality, integrity, and availability. This vulnerability was actively exploited in the wild in March 2011, has available Metasploit modules, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.2.154.13CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
<= 10.1.106.16CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
>= 9.0, <= 9.4.2CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:10.0:*:*:*:*:*:*:* | ||
10.0.1CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:10.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.