Vulnerability record · CVE-2011-2110 · published 16 June 2011
CVE-2011-2110: Adobe Flash Player memory corruption allows remote code execution
Adobe · Flash Player
Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux and Solaris, and 10.3.185.23 and earlier on Android, contains a memory corruption flaw (CWE-119) reachable through unspecified vectors. Adobe confirms it was exploited in the wild in June 2011, so it is a real, weaponized remote code execution issue rather than a theoretical one.
Description
Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in June 2011.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10.0 with confirmed in-the-wild exploitation and a very high EPSS probability make this a top-priority fix wherever Flash Player remains installed.
What it is
Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux and Solaris, and 10.3.185.23 and earlier on Android, contains a memory corruption flaw (CWE-119) reachable through unspecified vectors. Adobe confirms it was exploited in the wild in June 2011, so it is a real, weaponized remote code execution issue rather than a theoretical one.
Impact
A remote attacker can execute arbitrary code in the context of the Flash Player process, or crash it to cause a denial of service. Successful code execution gives the attacker the privileges of the user running the player.
Attack surface
Reached over the network (AV:N) with no authentication (Au:N) and low complexity (AC:L), typically by a victim loading attacker-controlled Flash content in a browser or player. The description does not specify the exact vectors, but no user interaction beyond rendering the content is implied by the vector.
Exploitation
Adobe and US-CERT references state it was exploited in the wild in June 2011; it is not listed in CISA KEV, and EPSS is very high (0.864, 99.7th percentile), consistent with active exploitation of an end-of-life product.
What to do
- Upgrade Flash Player to 10.3.181.26 or later on Windows, Mac OS X, Linux and Solaris, and to a fixed release above 10.3.185.23 on Android, per Adobe APSB11-18.
- Apply vendor errata for bundled or redistributed Flash (for example Red Hat RHSA-2011-0869) and any openSUSE updates.
- Remove or disable Flash Player where it is no longer required, since the product is end-of-life and no longer receives security fixes.
- Restrict browser and player execution of untrusted Flash content, and block Flash content from untrusted origins at the network or proxy layer.
Detection
- Hunt for Flash Player versions below 10.3.181.26 (or Android below 10.3.185.23) across endpoints using software inventory.
- Monitor for Flash Player process crashes or memory-corruption-related crash reports, which may indicate exploitation attempts.
- Review web proxy and DNS logs for Flash content (.swf) served from untrusted or newly seen domains around the June 2011 exploitation window and after.
- Use the OVAL definitions referenced for this CVE to scan hosts for vulnerable Flash installations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-2110 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-2110), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.