flash-plugin: crash and potential arbitrary code execution (APSB11-07)
Published Apr 13, 2011 ·Due Mar 24, 2022
8.8
HIGHCVSS 3.1
EPSS 99.41%
Description
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.
Affected products
No data.
Configuration 1
- < 10.2.154.27
Configuration 2
- ≤ 10.2.156.12
Configuration 3
- ≥ 9.0 · < 9.4.4
- ≥ 10.0 · ≤ 10.0.1
Configuration 5
- ≥ 9.0 · < 9.4.4
- ≥ 10.0 · < 10.0.3
Configuration 6
Configuration 7
Configuration 8
- 11.2
- 11.3
- 11.4
- 10
- 11
-
- Version 10.0StatusaffectedConstraints<10.0.3
- Version 9.0StatusaffectedConstraints<9.4.4
- Version
-
- Version 0StatusaffectedConstraints<2.6.19140
- Version
-
- Version 0StatusaffectedConstraints<10.2.154.27
- Version
-
- Version 10.0StatusaffectedConstraints<10.0.3
- Version 9.0StatusaffectedConstraints<9.4.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Adobe | Acrobat | n/a |
| |||||||||
| Adobe | Air | n/a |
| |||||||||
| Adobe | Flash Player | n/a |
| |||||||||
| Adobe | Reader | n/a |
|
Red Hat Enterprise Linux 6 Supplementary
flash-plugin-0:10.2.159.1-1.el6
Fixed · RHSA-2011:0451
Supplementary for Red Hat Enterprise Linux 5
flash-plugin-0:10.2.159.1-1.el5
Fixed · RHSA-2011:0451
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Supplementary | flash-plugin-0:10.2.159.1-1.el6 | Fixed | RHSA-2011:0451 |
| Supplementary for Red Hat Enterprise Linux 5 | flash-plugin-0:10.2.159.1-1.el5 | Fixed | RHSA-2011:0451 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Date Added
Mar 3, 2022
Patch Due
Mar 24, 2022
Required Action
The impacted product is end-of-life and should be disconnected if still in use.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 2, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (23 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 99.41% (0.99410) | 99.94th | v5 (v2026.06.15) |
| Aug 24, 2026 | 99.41% (0.99410) | 99.94th | v5 (v2026.06.15) |
| Jul 24, 2026 | 94.20% (0.94197) | 99.84th | v5 (v2026.06.15) |
| Jun 15, 2026 | 99.41% (0.99410) | 99.94th | v5 (v2026.06.15) |
| Mar 17, 2025 | 93.70% (0.93698) | 99.85th | v4 (v2025.03.14) |
| Dec 17, 2024 | 95.20% (0.95197) | 99.51th | v3 (v2023.03.01) |
| Dec 12, 2024 | 96.45% (0.96447) | 99.64th | v3 (v2023.03.01) |
| Sep 8, 2024 | 96.09% (0.96091) | 99.54th | v3 (v2023.03.01) |
| Jun 13, 2024 | 97.14% (0.97142) | 99.80th | v3 (v2023.03.01) |
| Apr 29, 2024 | 96.93% (0.96927) | 99.71th | v3 (v2023.03.01) |
| Mar 11, 2024 | 97.16% (0.97164) | 99.79th | v3 (v2023.03.01) |
| Feb 2, 2024 | 97.01% (0.97009) | 99.69th | v3 (v2023.03.01) |
| Jan 21, 2024 | 97.25% (0.97249) | 99.82th | v3 (v2023.03.01) |
| Dec 2, 2023 | 96.94% (0.96942) | 99.66th | v3 (v2023.03.01) |
| Oct 12, 2023 | 96.97% (0.96972) | 99.64th | v3 (v2023.03.01) |
| Aug 20, 2023 | 96.65% (0.96645) | 99.46th | v3 (v2023.03.01) |
| Jun 26, 2023 | 97.12% (0.97117) | 99.66th | v3 (v2023.03.01) |
| Mar 9, 2023 | 97.42% (0.97425) | 99.87th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.45% (0.97453) | 99.90th | v3 (v2023.03.01) |
| Mar 6, 2023 | 82.46% (0.82460) | 99.57th | v2 (v2022.01.01) |
| Jun 3, 2022 | 82.46% (0.82460) | 99.53th | v2 (v2022.01.01) |
| Mar 16, 2022 | 82.97% (0.82974) | 99.51th | v2 (v2022.01.01) |
| Feb 4, 2022 | 83.78% (0.83779) | 99.54th | v2 (v2022.01.01) |
References (31)
- http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploitation.aspx x_refsource_MISCNot Applicable
- http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html x_refsource_MISCExploit
- http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html x_refsource_MISCExploitIssue Tracking
- http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html x_refsource_CONFIRMRelease Notes
- http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00004.html vendor-advisoryx_refsource_SUSEMailing ListPatch
- http://secunia.com/advisories/44119 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/44141 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/44149 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/blog/210/ x_refsource_MISCBroken LinkVendor Advisory
- http://securityreason.com/securityalert/8204 third-party-advisoryx_refsource_SREASONThird Party Advisory
- http://securityreason.com/securityalert/8292 third-party-advisoryx_refsource_SREASONThird Party Advisory
- http://www.adobe.com/support/security/advisories/apsa11-02.html x_refsource_CONFIRMBroken LinkVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb11-07.html x_refsource_CONFIRMBroken LinkVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb11-08.html x_refsource_CONFIRMBroken LinkVendor Advisory
- http://www.exploit-db.com/exploits/17175 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- http://www.kb.cert.org/vuls/id/230057 third-party-advisoryx_refsource_CERT-VNBroken LinkThird Party AdvisoryUS Government Resource
- http://www.redhat.com/support/errata/RHSA-2011-0451.html vendor-advisoryx_refsource_REDHATBroken LinkVendor Advisory
- http://www.securityfocus.com/bid/47314 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1025324 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1025325 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2011/0922 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2011/0923 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2011/0924 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- https://access.redhat.com/security/cve/CVE-2011-0611 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=695546 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66681 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2011-0611
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14175 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-0611 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2011-0611
Change history (0)
No recorded changes yet.