← Vulnerability feed

Vulnerability record · CVE-2011-0609 · published 15 March 2011

CVE-2011-0609: Adobe Flash Player and Reader/AIR unspecified code execution via crafted SWF

Adobe · Flash Player

An unspecified vulnerability in Adobe Flash Player, Adobe AIR, and the Authplay.dll component of Adobe Reader and Acrobat allows remote attackers to execute arbitrary code or crash the application via crafted Flash content, demonstrated with a .swf embedded in an Excel spreadsheet. The flaw was exploited in the wild in March 2011, and the affected products are long past end of life.

7.8 CVSS 3.1 High CISA KEV since 8 Jun 2022 EPSS 64% · top 0.8%
7.8CVSS 3.1 base score, v2 9.3
64%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
7Affected product versions listed by NVD
45References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw allows remote code execution, is confirmed exploited in the wild and in CISA KEV with high EPSS, but the affected products are end-of-life and the vector requires user interaction.

What it is

An unspecified vulnerability in Adobe Flash Player, Adobe AIR, and the Authplay.dll component of Adobe Reader and Acrobat allows remote attackers to execute arbitrary code or crash the application via crafted Flash content, demonstrated with a .swf embedded in an Excel spreadsheet. The flaw was exploited in the wild in March 2011, and the affected products are long past end of life.

Impact

An attacker who gets a victim to open the crafted content can run arbitrary code in the context of the affected process, or cause a denial of service through an application crash.

Attack surface

Reached by delivering crafted Flash content, such as a .swf embedded in a document, to a user who must open or render it; the CVSS vector indicates local access with user interaction and no privileges required. No authentication is needed on the attacker side.

Exploitation

Listed in CISA KEV since 2022-06-08 with a required action to disconnect the end-of-life product, and the description states it was exploited in the wild in March 2011. EPSS 30-day probability is 0.66821 (99.253 percentile), indicating high predicted exploitation activity.

What to do

  • Remove or disconnect all end-of-life Adobe Flash Player, Adobe AIR, and Adobe Reader/Acrobat 9.x and 10.x installations, per the CISA KEV required action.
  • If any legacy installation cannot be removed, isolate it from untrusted content and network access and block Flash (.swf) content at email and web gateways.
  • Apply the vendor fixes referenced in Adobe advisory APSA11-01/APSB11-06 and the Google Chrome, openSUSE and Red Hat errata for any still-supported platform.
  • Disable or remove the Authplay.dll/AuthPlayLib.bundle Flash component from Reader and Acrobat where those versions remain in use.
  • Block or strip embedded Flash objects in office documents and spreadsheets at the mail and endpoint layers.

Detection

  • Hunt for processes loading Authplay.dll or AuthPlayLib.bundle, or for Flash Player/AIR binaries, on endpoints that should no longer run them.
  • Monitor for office applications (Excel, Word, Reader, Acrobat) spawning child processes such as cmd.exe, powershell.exe or script interpreters.
  • Alert on .swf files or Flash objects embedded in office documents and email attachments entering the environment.
  • Review proxy and email logs for delivery of .swf content or documents containing embedded Flash objects to legacy hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2011-0609 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Adobe Flash Player Unspecified Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 22 June 2022.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blogs.adobe.com/asset/2011/03/background-on-apsa11-01-patch-schedule.html Broken Link
http://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates_15.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html Mailing ListThird Party Advisory
http://secunia.com/advisories/43751 Broken Link
http://secunia.com/advisories/43757 Broken Link
http://secunia.com/advisories/43772 Broken Link
http://secunia.com/advisories/43856 Broken Link
http://securityreason.com/securityalert/8152 Broken Link
http://www.adobe.com/support/security/advisories/apsa11-01.html Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb11-06.html Not Applicable
http://www.kb.cert.org/vuls/id/192052 Third Party AdvisoryUS Government Resource
http://www.redhat.com/support/errata/RHSA-2011-0372.html Broken Link
http://www.securityfocus.com/bid/46860 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1025210 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1025211 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1025238 Broken LinkThird Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2011/0655 Broken Link
http://www.vupen.com/english/advisories/2011/0656 Broken Link
http://www.vupen.com/english/advisories/2011/0688 Broken Link
http://www.vupen.com/english/advisories/2011/0732 Broken Link
https://exchange.xforce.ibmcloud.com/vulnerabilities/66078 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14147 Broken Link
http://blogs.adobe.com/asset/2011/03/background-on-apsa11-01-patch-schedule.html Broken Link
http://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates_15.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html Mailing ListThird Party Advisory
http://secunia.com/advisories/43751 Broken Link
http://secunia.com/advisories/43757 Broken Link
http://secunia.com/advisories/43772 Broken Link
http://secunia.com/advisories/43856 Broken Link
http://securityreason.com/securityalert/8152 Broken Link
http://www.adobe.com/support/security/advisories/apsa11-01.html Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb11-06.html Not Applicable
http://www.kb.cert.org/vuls/id/192052 Third Party AdvisoryUS Government Resource
http://www.redhat.com/support/errata/RHSA-2011-0372.html Broken Link
http://www.securityfocus.com/bid/46860 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1025210 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1025211 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1025238 Broken LinkThird Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2011/0655 Broken Link
http://www.vupen.com/english/advisories/2011/0656 Broken Link

Track CVE-2011-0609 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-10585Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that can lead to heap corruption when processing a crafted HTML page. It affec…KEVEPSS 5.4%analysed9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-1019Adobe Flash Player memory corruption allows code executionAdobe Flash Player 21.0.0.197 and earlier contains an unspecified memory corruption flaw that can crash the application or allow arbitrary code execu…KEVEPSS 22%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed9.8CVE-2015-5122Adobe Flash Player ActionScript 3 Use-After-Free in DisplayObjectA use-after-free flaw in the DisplayObject class of Adobe Flash Player's ActionScript 3 implementation is triggered by crafted Flash content that mis…KEVEPSS 94%analysed9.8CVE-2015-5119Adobe Flash Player ActionScript 3 ByteArray use-after-freeA use-after-free flaw exists in the ByteArray class of the ActionScript 3 implementation in Adobe Flash Player. Crafted Flash content that overrides …KEVEPSS 99%analysed9.8CVE-2015-3113Adobe Flash Player heap buffer overflow allows remote code executionAdobe Flash Player contains a heap-based buffer overflow (CWE-122/CWE-787) reachable through unspecified vectors. It affects Flash Player before 13.0…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2011-0609), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.