Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 82.4%; technical severity is CVSS 7.8.
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.
Who should care
- Teams operating Acrobat, Air, Flash Player +2 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Acrobat, Air, Flash Player +2 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Apple Security patch HT4435
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Advisory
- Adobe Security advisory Apsa10 01Adobe · Vendor sourceVerification pending ↗
- Adobe Security advisory APSB10-14Adobe · Vendor sourceVerification pending ↗
- Adobe Security advisory APSB10-15Adobe · Vendor sourceVerification pending ↗
- Red Hat Security advisory RHSA 2010 0464Red Hat · Vendor sourceVerification pending ↗
- Red Hat Security advisory RHSA 2010 0470Red Hat · Vendor sourceVerification pending ↗
Technical details
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CWE
- CWE-787
- Affected versions
- Adobe Acrobat (Start Including 8.0, End Excluding 8.2.3 | Start Including 9.0, End Excluding 9.3.3); Adobe Air (End Excluding 2.0.2.12610); Adobe Flash Player (End Excluding 9.0.277.0 | Start Including 10.0, End Excluding 10.1.53.64); Opensuse Opensuse (Start Including 11.0, End Including 11.2); Suse Linux Enterprise (Version 10.0 | Version 11.0 | Version 11.0)
- Fixed versions
- Adobe Acrobat (Fixed from 8.2.3, 9.3.3); Adobe Air (Fixed from 2.0.2.12610); Adobe Flash Player (Fixed from 9.0.277.0, 10.1.53.64)
- Published
- 8 June 2010
- Attack vector
- Local
- Privileges required
- None
- User interaction
- Required
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 82.4%
- Signal calculated at 81
External references
- Apple Third-party advisory Msg00000
- CERT/CC Government advisory 486225
- CISA Government advisory CVE-2010-1297
- Exploit information from blog.zynamics.com
- Community Websense Exploit information Having Fun With Adobe 0 Day Exploits
- Lists Opensuse Third-party advisory Msg00000
- Lists Opensuse Third-party advisory Msg00001
- Secunia Technical reference
- Secunia Technical reference
- Secunia Technical reference
- Secunia Technical reference
- Secunia Technical reference