CVE-2012-1535 is an unspecified vulnerability in Adobe Flash Player versions prior to 11.3.300.271 on Windows/Mac OS X and 11.2.202.238 on Linux, allowing remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content. This vulnerability has a high CVSS score of 7.8, indicating a high impact with potential for complete compromise of confidentiality, integrity, and availability, and requires user interaction (e.g., opening a malicious Word document). It was actively exploited in the wild in August 2012, with exploit code available in Metasploit and significant community discussion and media coverage confirming its widespread impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.3.300.271CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
< 11.2.202.238CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.