Vulnerability record · CVE-2012-2034 · published 9 June 2012
CVE-2012-2034: Adobe Flash Player and AIR memory corruption code execution
Adobe · Flash Player
Adobe Flash Player and Adobe AIR contain a memory corruption flaw (CWE-119) that allows attackers to execute arbitrary code or cause a denial of service. The vulnerability affects multiple versions across Windows, Mac OS X, Linux, and Android, and is distinct from CVE-2012-2037.
Description
Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2037.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe vulnerability is in CISA's Known Exploited Vulnerabilities catalog and allows remote code execution, though exploitation requires user interaction and the product is end-of-life.
What it is
Adobe Flash Player and Adobe AIR contain a memory corruption flaw (CWE-119) that allows attackers to execute arbitrary code or cause a denial of service. The vulnerability affects multiple versions across Windows, Mac OS X, Linux, and Android, and is distinct from CVE-2012-2037.
Impact
An attacker can execute arbitrary code in the context of the affected process or crash it, leading to full compromise of the user's system or a denial of service.
Attack surface
The flaw is reachable over the network (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R), such as visiting a malicious webpage or opening a crafted file that loads Flash content.
Exploitation
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2022-03-28, indicating active exploitation in the wild; EPSS estimates a 7.8% probability of exploitation in the next 30 days (94th percentile).
What to do
- Apply the vendor patches referenced in Adobe Security Bulletin APSB12-14 and the corresponding Linux distribution advisories (RHSA-2012-0722, openSUSE security announcements).
- If patching is not possible, disconnect or remove end-of-life Adobe Flash Player and AIR installations, as recommended by CISA.
- Disable or uninstall Flash Player browser plug-ins and block Flash content via browser or enterprise policy.
- Restrict user ability to run untrusted Flash content and enforce application whitelisting where feasible.
Detection
- Monitor for network connections or file writes associated with known Flash exploit payloads, focusing on processes loading Flash content.
- Use endpoint detection to flag abnormal process behavior originating from Flash Player or AIR, such as unexpected child processes or memory corruption indicators.
- Review proxy and IDS logs for requests to known malicious Flash exploit hosts or malformed SWF files.
- Audit systems for the presence of vulnerable Flash Player or AIR versions and alert on continued use of end-of-life software.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2012-2034 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Adobe Flash Player Memory Corruption Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 18 April 2022.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00006.html | Mailing ListThird Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00007.html | Mailing ListThird Party Advisory |
| http://rhn.redhat.com/errata/RHSA-2012-0722.html | Third Party Advisory |
| http://www.adobe.com/support/security/bulletins/apsb12-14.html | Vendor Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00006.html | Mailing ListThird Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00007.html | Mailing ListThird Party Advisory |
| http://rhn.redhat.com/errata/RHSA-2012-0722.html | Third Party Advisory |
| http://www.adobe.com/support/security/bulletins/apsb12-14.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-2034 | US Government Resource |
Track CVE-2012-2034 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-2034), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.