← Vulnerability feed

Vulnerability record · CVE-2011-0611 · published 13 April 2011

CVE-2011-0611: Adobe Flash Player type confusion allows remote code execution

Adobe · Flash Player

Adobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Flash content, including a .swf embedded in a Microsoft Office document. Successful exploitation allows arbitrary code execution or an application crash, and the flaw was exploited in the wild in April 2011.

8.8 CVSS 3.1 High CISA KEV since 3 Mar 2022 EPSS 99% · top 0.1% CWE-843 · Type confusion
8.8CVSS 3.1 base score, v2 9.3
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
7Affected product versions listed by NVD
51References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityRemote code execution with public exploits, in-the-wild exploitation and KEV listing, though the affected products are end-of-life.

What it is

Adobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Flash content, including a .swf embedded in a Microsoft Office document. Successful exploitation allows arbitrary code execution or an application crash, and the flaw was exploited in the wild in April 2011.

Impact

An attacker can execute arbitrary code in the context of the affected application, or crash it, giving full control of the process on a victim machine.

Attack surface

Reached remotely over the network by delivering crafted Flash content (for example an Office document with an embedded .swf) that the victim must open or render; no authentication is required but user interaction is needed per the CVSS vector (AV:N/AC:L/PR:N/UI:R).

Exploitation

Listed in CISA KEV since 2022-03-03 and exploited in the wild in April 2011, with public exploit references; EPSS 30-day probability is 0.9941 (99.94th percentile).

What to do

  • Patch or remove affected Adobe Flash Player, AIR, Reader and Acrobat versions; note Flash Player is end-of-life and CISA advises disconnecting it if still in use.
  • Apply the vendor updates referenced in Adobe advisories APSB11-07 and APSB11-08 and the corresponding Linux distribution patches.
  • Disable or block Flash content rendering in browsers, Office documents and PDF readers where possible.
  • Restrict opening of untrusted Office documents and PDFs containing embedded Flash content via email and web gateways.

Detection

  • Hunt for processes loading Authplay.dll or Flash Player libraries spawning unexpected child processes.
  • Monitor for Office or PDF reader processes making outbound network connections or writing executables to disk.
  • Search endpoint logs for crashes in Flash Player, AIR, Reader or Acrobat consistent with malformed .swf content.
  • Review proxy and email logs for .swf attachments or embedded Flash objects delivered to users.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2011-0611 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Adobe Flash Player Remote Code Execution Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 24 March 2022.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploi Not Applicable
http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html Exploit
http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html ExploitIssue Tracking
http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html Release Notes
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00004.html Mailing ListPatch
http://secunia.com/advisories/44119 Broken LinkVendor Advisory
http://secunia.com/advisories/44141 Broken LinkVendor Advisory
http://secunia.com/advisories/44149 Broken LinkVendor Advisory
http://secunia.com/blog/210/ Broken LinkVendor Advisory
http://securityreason.com/securityalert/8204 Third Party Advisory
http://securityreason.com/securityalert/8292 Third Party Advisory
http://www.adobe.com/support/security/advisories/apsa11-02.html Broken LinkVendor Advisory
http://www.adobe.com/support/security/bulletins/apsb11-07.html Broken LinkVendor Advisory
http://www.adobe.com/support/security/bulletins/apsb11-08.html Broken LinkVendor Advisory
http://www.exploit-db.com/exploits/17175 ExploitThird Party AdvisoryVDB Entry
http://www.kb.cert.org/vuls/id/230057 Broken LinkThird Party AdvisoryUS Government Resource
http://www.redhat.com/support/errata/RHSA-2011-0451.html Broken LinkVendor Advisory
http://www.securityfocus.com/bid/47314 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1025324 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1025325 Broken LinkThird Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2011/0922 Broken LinkVendor Advisory
http://www.vupen.com/english/advisories/2011/0923 Broken LinkVendor Advisory
http://www.vupen.com/english/advisories/2011/0924 Broken LinkVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/66681 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14175 Broken Link
http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploi Not Applicable
http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html Exploit
http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html ExploitIssue Tracking
http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html Release Notes
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00004.html Mailing ListPatch
http://secunia.com/advisories/44119 Broken LinkVendor Advisory
http://secunia.com/advisories/44141 Broken LinkVendor Advisory
http://secunia.com/advisories/44149 Broken LinkVendor Advisory
http://secunia.com/blog/210/ Broken LinkVendor Advisory
http://securityreason.com/securityalert/8204 Third Party Advisory
http://securityreason.com/securityalert/8292 Third Party Advisory
http://www.adobe.com/support/security/advisories/apsa11-02.html Broken LinkVendor Advisory
http://www.adobe.com/support/security/bulletins/apsb11-07.html Broken LinkVendor Advisory
http://www.adobe.com/support/security/bulletins/apsb11-08.html Broken LinkVendor Advisory
http://www.exploit-db.com/exploits/17175 ExploitThird Party AdvisoryVDB Entry

Track CVE-2011-0611 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-10585Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that can lead to heap corruption when processing a crafted HTML page. It affec…KEVEPSS 5.4%analysed9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-1019Adobe Flash Player memory corruption allows code executionAdobe Flash Player 21.0.0.197 and earlier contains an unspecified memory corruption flaw that can crash the application or allow arbitrary code execu…KEVEPSS 22%analysed9.8CVE-2015-5123Adobe Flash Player ActionScript 3 BitmapData use-after-freeAdobe Flash Player contains a use-after-free in the ActionScript 3 BitmapData class, triggered by crafted Flash content that overrides a valueOf func…KEVEPSS 19%analysed9.8CVE-2015-5122Adobe Flash Player ActionScript 3 Use-After-Free in DisplayObjectA use-after-free flaw in the DisplayObject class of Adobe Flash Player's ActionScript 3 implementation is triggered by crafted Flash content that mis…KEVEPSS 94%analysed9.8CVE-2015-5119Adobe Flash Player ActionScript 3 ByteArray use-after-freeA use-after-free flaw exists in the ByteArray class of the ActionScript 3 implementation in Adobe Flash Player. Crafted Flash content that overrides …KEVEPSS 99%analysed9.8CVE-2015-3113Adobe Flash Player heap buffer overflow allows remote code executionAdobe Flash Player contains a heap-based buffer overflow (CWE-122/CWE-787) reachable through unspecified vectors. It affects Flash Player before 13.0…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2011-0611), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.