Vulnerability record · CVE-2011-0611 · published 13 April 2011
CVE-2011-0611: Adobe Flash Player type confusion allows remote code execution
Adobe · Flash Player
Adobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Flash content, including a .swf embedded in a Microsoft Office document. Successful exploitation allows arbitrary code execution or an application crash, and the flaw was exploited in the wild in April 2011.
Description
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityRemote code execution with public exploits, in-the-wild exploitation and KEV listing, though the affected products are end-of-life.
What it is
Adobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Flash content, including a .swf embedded in a Microsoft Office document. Successful exploitation allows arbitrary code execution or an application crash, and the flaw was exploited in the wild in April 2011.
Impact
An attacker can execute arbitrary code in the context of the affected application, or crash it, giving full control of the process on a victim machine.
Attack surface
Reached remotely over the network by delivering crafted Flash content (for example an Office document with an embedded .swf) that the victim must open or render; no authentication is required but user interaction is needed per the CVSS vector (AV:N/AC:L/PR:N/UI:R).
Exploitation
Listed in CISA KEV since 2022-03-03 and exploited in the wild in April 2011, with public exploit references; EPSS 30-day probability is 0.9941 (99.94th percentile).
What to do
- Patch or remove affected Adobe Flash Player, AIR, Reader and Acrobat versions; note Flash Player is end-of-life and CISA advises disconnecting it if still in use.
- Apply the vendor updates referenced in Adobe advisories APSB11-07 and APSB11-08 and the corresponding Linux distribution patches.
- Disable or block Flash content rendering in browsers, Office documents and PDF readers where possible.
- Restrict opening of untrusted Office documents and PDFs containing embedded Flash content via email and web gateways.
Detection
- Hunt for processes loading Authplay.dll or Flash Player libraries spawning unexpected child processes.
- Monitor for Office or PDF reader processes making outbound network connections or writing executables to disk.
- Search endpoint logs for crashes in Flash Player, AIR, Reader or Acrobat consistent with malformed .swf content.
- Review proxy and email logs for .swf attachments or embedded Flash objects delivered to users.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2011-0611 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Adobe Flash Player Remote Code Execution Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 24 March 2022.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-0611 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-0611), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.