← Vulnerability feed

Vulnerability record · CVE-2010-1297 · published 8 June 2010

CVE-2010-1297: Adobe Flash Player, AIR, Reader and Acrobat memory corruption via crafted SWF

Adobe · Air

Adobe Flash Player, AIR, Reader and Acrobat contain an out-of-bounds write (CWE-787) in the ActionScript Virtual Machine 2 newfunction instruction, reachable through crafted SWF content. Successful exploitation causes memory corruption that can lead to arbitrary code execution or a denial of service. The flaw was exploited in the wild in June 2010 and the affected products are end-of-life.

7.8 CVSS 3.1 High CISA KEV since 8 Jun 2022 EPSS 82% · top 0.4% CWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score, v2 9.3
82%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
5Affected product versions listed by NVD
87References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw allows remote code execution, was exploited in the wild, is in CISA KEV, and the affected products are end-of-life with no supported patching path.

What it is

Adobe Flash Player, AIR, Reader and Acrobat contain an out-of-bounds write (CWE-787) in the ActionScript Virtual Machine 2 newfunction instruction, reachable through crafted SWF content. Successful exploitation causes memory corruption that can lead to arbitrary code execution or a denial of service. The flaw was exploited in the wild in June 2010 and the affected products are end-of-life.

Impact

An attacker can execute arbitrary code in the context of the affected application or crash it, giving full control of the process on the victim's system. No privilege escalation beyond the application's own context is described.

Attack surface

Reached by getting a victim to open or render a crafted SWF file, typically embedded in a web page or document, so user interaction is required. The CVSS vector (AV:L/UI:R/PR:N) indicates local access with no authentication but required user action.

Exploitation

The record states the vulnerability was exploited in the wild in June 2010, it is listed in CISA KEV, and an Exploit reference is present; EPSS is 0.82365 (99.6th percentile). No ransomware campaign use is documented.

What to do

  • Patch to the fixed versions: Flash Player 9.0.277.0 or 10.1.53.64, AIR 2.0.2.12610, Reader/Acrobat 9.3.3 or 8.2.3.
  • Since the affected products are end-of-life, disconnect or remove them if they cannot be updated.
  • Disable or block Flash and SWF content rendering in browsers, email clients and document readers.
  • Apply the vendor and Linux distribution advisories referenced in the record for bundled Flash/AIR packages.
  • Restrict execution of untrusted SWF files and documents from external sources.

Detection

  • Hunt for processes loading authplay.dll or Flash/AIR/Reader components spawning unexpected child processes.
  • Monitor for crashes or memory corruption events in Flash Player, AIR, Reader and Acrobat.
  • Search endpoint and proxy logs for SWF files delivered from untrusted or newly registered domains.
  • Review EDR telemetry for code execution originating from document readers or browser plugin processes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2010-1297 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Adobe Flash Player Memory Corruption Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 22 June 2022.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blog.zynamics.com/2010/06/09/analyzing-the-currently-exploited-0-day-for-adobe-reader-and-adobe-flash/ Exploit
http://community.websense.com/blogs/securitylabs/archive/2010/06/09/having-fun-with-adobe-0-day-exploits.aspx Broken Link
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751 Broken Link
http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00000.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html Mailing ListThird Party Advisory
http://secunia.com/advisories/40026 Broken LinkVendor Advisory
http://secunia.com/advisories/40034 Broken LinkVendor Advisory
http://secunia.com/advisories/40144 Broken Link
http://secunia.com/advisories/40545 Broken Link
http://secunia.com/advisories/43026 Broken Link
http://security.gentoo.org/glsa/glsa-201101-09.xml Third Party Advisory
http://securitytracker.com/id?1024057 Broken LinkThird Party AdvisoryVDB Entry
http://securitytracker.com/id?1024058 Broken LinkThird Party AdvisoryVDB Entry
http://securitytracker.com/id?1024085 Broken LinkThird Party AdvisoryVDB Entry
http://securitytracker.com/id?1024086 Broken LinkThird Party AdvisoryVDB Entry
http://support.apple.com/kb/HT4435 Broken Link
http://www.adobe.com/support/security/advisories/apsa10-01.html Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb10-14.html Not Applicable
http://www.adobe.com/support/security/bulletins/apsb10-15.html Not Applicable
http://www.exploit-db.com/exploits/13787 Third Party AdvisoryVDB Entry
http://www.kb.cert.org/vuls/id/486225 Third Party AdvisoryUS Government Resource
http://www.osvdb.org/65141 Broken Link
http://www.redhat.com/support/errata/RHSA-2010-0464.html Broken Link
http://www.redhat.com/support/errata/RHSA-2010-0470.html Broken Link
http://www.securityfocus.com/bid/40586 Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/40759 Broken LinkThird Party AdvisoryVDB Entry
http://www.turbolinux.co.jp/security/2010/TLSA-2010-19j.txt Broken Link
http://www.us-cert.gov/cas/techalerts/TA10-159A.html Third Party AdvisoryUS Government Resource
http://www.us-cert.gov/cas/techalerts/TA10-162A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2010/1348 Broken LinkVendor Advisory
http://www.vupen.com/english/advisories/2010/1349 Broken LinkVendor Advisory
http://www.vupen.com/english/advisories/2010/1421 Broken Link
http://www.vupen.com/english/advisories/2010/1432 Broken Link
http://www.vupen.com/english/advisories/2010/1434 Broken Link
http://www.vupen.com/english/advisories/2010/1453 Broken Link
http://www.vupen.com/english/advisories/2010/1482 Broken Link
http://www.vupen.com/english/advisories/2010/1522 Broken Link
http://www.vupen.com/english/advisories/2010/1636 Broken Link
http://www.vupen.com/english/advisories/2010/1793 Broken Link

Track CVE-2010-1297 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2016-1019Adobe Flash Player memory corruption allows code executionAdobe Flash Player 21.0.0.197 and earlier contains an unspecified memory corruption flaw that can crash the application or allow arbitrary code execu…KEVEPSS 22%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed9.8CVE-2015-5122Adobe Flash Player ActionScript 3 Use-After-Free in DisplayObjectA use-after-free flaw in the DisplayObject class of Adobe Flash Player's ActionScript 3 implementation is triggered by crafted Flash content that mis…KEVEPSS 94%analysed9.8CVE-2015-5119Adobe Flash Player ActionScript 3 ByteArray use-after-freeA use-after-free flaw exists in the ByteArray class of the ActionScript 3 implementation in Adobe Flash Player. Crafted Flash content that overrides …KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2010-1297), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.