Vulnerability record · CVE-2011-0609 · published 15 March 2011
CVE-2011-0609: Adobe Flash Player and Reader/AIR unspecified code execution via crafted SWF
Adobe · Flash Player
An unspecified vulnerability in Adobe Flash Player, Adobe AIR, and the Authplay.dll component of Adobe Reader and Acrobat allows remote attackers to execute arbitrary code or crash the application via crafted Flash content, demonstrated with a .swf embedded in an Excel spreadsheet. The flaw was exploited in the wild in March 2011, and the affected products are long past end of life.
Description
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows remote code execution, is confirmed exploited in the wild and in CISA KEV with high EPSS, but the affected products are end-of-life and the vector requires user interaction.
What it is
An unspecified vulnerability in Adobe Flash Player, Adobe AIR, and the Authplay.dll component of Adobe Reader and Acrobat allows remote attackers to execute arbitrary code or crash the application via crafted Flash content, demonstrated with a .swf embedded in an Excel spreadsheet. The flaw was exploited in the wild in March 2011, and the affected products are long past end of life.
Impact
An attacker who gets a victim to open the crafted content can run arbitrary code in the context of the affected process, or cause a denial of service through an application crash.
Attack surface
Reached by delivering crafted Flash content, such as a .swf embedded in a document, to a user who must open or render it; the CVSS vector indicates local access with user interaction and no privileges required. No authentication is needed on the attacker side.
Exploitation
Listed in CISA KEV since 2022-06-08 with a required action to disconnect the end-of-life product, and the description states it was exploited in the wild in March 2011. EPSS 30-day probability is 0.66821 (99.253 percentile), indicating high predicted exploitation activity.
What to do
- Remove or disconnect all end-of-life Adobe Flash Player, Adobe AIR, and Adobe Reader/Acrobat 9.x and 10.x installations, per the CISA KEV required action.
- If any legacy installation cannot be removed, isolate it from untrusted content and network access and block Flash (.swf) content at email and web gateways.
- Apply the vendor fixes referenced in Adobe advisory APSA11-01/APSB11-06 and the Google Chrome, openSUSE and Red Hat errata for any still-supported platform.
- Disable or remove the Authplay.dll/AuthPlayLib.bundle Flash component from Reader and Acrobat where those versions remain in use.
- Block or strip embedded Flash objects in office documents and spreadsheets at the mail and endpoint layers.
Detection
- Hunt for processes loading Authplay.dll or AuthPlayLib.bundle, or for Flash Player/AIR binaries, on endpoints that should no longer run them.
- Monitor for office applications (Excel, Word, Reader, Acrobat) spawning child processes such as cmd.exe, powershell.exe or script interpreters.
- Alert on .swf files or Flash objects embedded in office documents and email attachments entering the environment.
- Review proxy and email logs for delivery of .swf content or documents containing embedded Flash objects to legacy hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2011-0609 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Adobe Flash Player Unspecified Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 22 June 2022.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-0609 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-0609), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.