Vulnerability record · CVE-2010-3653 · published 26 October 2010
CVE-2010-3653: Adobe Shockwave Player Director module memory corruption via crafted rcsL chunk
Adobe · Shockwave Player
Adobe Shockwave Player before 11.5.9.615 contains a memory corruption flaw in the Director module (dirapi.dll). A crafted Director movie with a malicious rcsL chunk can corrupt memory, allowing remote code execution or denial of service. The vulnerability was exploited in the wild in October 2010.
Description
The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie with a crafted rcsL chunk containing a field whose value is used as a pointer offset, as exploited in the wild in October 2010. NOTE: some of these details are obtained from third party information.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe vulnerability allows remote code execution, has public exploits, and was exploited in the wild, but requires user interaction and affects an older, less prevalent product.
What it is
Adobe Shockwave Player before 11.5.9.615 contains a memory corruption flaw in the Director module (dirapi.dll). A crafted Director movie with a malicious rcsL chunk can corrupt memory, allowing remote code execution or denial of service. The vulnerability was exploited in the wild in October 2010.
Impact
An attacker can execute arbitrary code in the context of the user running Shockwave Player, or crash the application. Successful exploitation could lead to full system compromise.
Attack surface
The flaw is reached by loading a malicious Director movie, typically delivered via a web page or file. No authentication is required, but some user interaction (e.g., visiting a page or opening a file) is needed to trigger the vulnerable component.
Exploitation
Exploits are publicly available (Exploit-DB, SecurityFocus) and the vulnerability was exploited in the wild in October 2010. It is not listed in CISA KEV, but EPSS indicates a high probability of exploitation activity.
What to do
- Update Adobe Shockwave Player to version 11.5.9.615 or later immediately.
- If patching is not possible, disable or remove the Shockwave Player browser plugin.
- Restrict the ability to load untrusted Director movies from the internet or email.
- Apply network filtering to block known malicious Shockwave content where feasible.
Detection
- Monitor for processes loading dirapi.dll and subsequently spawning unusual child processes or making network connections.
- Inspect web proxy or email logs for Shockwave (.dir, .dcr) files from untrusted sources.
- Use endpoint detection to flag crashes in dirapi.dll or Shockwave Player with memory corruption indicators.
- Search for known exploit signatures or shellcode patterns associated with the rcsL chunk.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-3653 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-3653), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.