Vulnerability record · CVE-2010-3654 · published 29 October 2010
CVE-2010-3654: Adobe Flash Player and Reader memory corruption via crafted SWF
Adobe · Flash Player
Adobe Flash Player (before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux and Solaris, and 10.1.95.1 on Android) and authplay.dll in Adobe Reader and Acrobat 9.x through 9.4 contain a memory corruption flaw (CWE-119) triggered by crafted SWF content. It allows remote code execution or denial of service and was exploited in the wild in October 2010, making it a serious client-side risk for unpatched systems.
Description
Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content, as exploited in the wild in October 2010.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with confirmed in-the-wild exploitation and very high EPSS, though the flaw is old and patched, so risk is concentrated on unpatched or legacy systems.
What it is
Adobe Flash Player (before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux and Solaris, and 10.1.95.1 on Android) and authplay.dll in Adobe Reader and Acrobat 9.x through 9.4 contain a memory corruption flaw (CWE-119) triggered by crafted SWF content. It allows remote code execution or denial of service and was exploited in the wild in October 2010, making it a serious client-side risk for unpatched systems.
Impact
An attacker can execute arbitrary code in the context of the affected application or crash it, giving full control of confidentiality, integrity and availability per the CVSS vector. In practice this means code execution on the victim's machine through a malicious SWF.
Attack surface
Reached remotely over the network by delivering crafted SWF content to Flash Player or to the authplay component embedded in Reader/Acrobat; no authentication is required, but the CVSS vector shows medium attack complexity and typically requires the user to open or render the malicious content.
Exploitation
The description states it was exploited in the wild in October 2010 and one reference is tagged Exploit, while EPSS is high (0.69679, 99.3rd percentile); it is not listed in CISA KEV.
What to do
- Update Flash Player to 9.0.289.0 or later, or 10.1.102.64 or later (10.1.95.1 on Android), and apply the corresponding Adobe Reader/Acrobat updates referenced in Adobe advisories APSA10-05, APSB10-26 and APSB10-28.
- Apply vendor patches for Reader/Acrobat authplay.dll and for Linux distributions (Red Hat, openSUSE, Gentoo) and Apple/Solaris platforms listed in the references.
- Disable or remove Flash content rendering where it is not required, and disable JavaScript/embedded content in Reader and Acrobat if feasible.
- Block or restrict untrusted SWF files at email and web gateways, and enforce browser plug-in click-to-play so SWF content does not render automatically.
Detection
- Monitor for Reader, Acrobat or Flash Player processes spawning child processes or making unexpected network connections, which can indicate successful exploitation.
- Hunt for crash reports or event logs from Flash Player, Reader or Acrobat referencing memory corruption or authplay module faults.
- Search email and web proxy logs for SWF attachments or downloads from untrusted sources delivered around the exploitation window.
- Use endpoint detection to flag known exploit artifacts or shellcode behavior in processes loading authplay.dll, AuthPlayLib.bundle or libauthplay.so.0.0.0.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-3654 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-3654), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.