Back

HIGH KEV

flash-plugin: Arbitrary code execution by opening a specially-crafted PDF file with malicious SWF content (APSA10-01)

Published Jun 8, 2010 ·Due Jun 22, 2022

Description

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (49)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Jun 8, 2010
Updated Oct 22, 2025
Reserved Apr 6, 2010
CISA Vulnrichment
Updated Feb 4, 2025
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Jun 4, 2010