First published: Wed Dec 07 2011(Updated: )
Common Vulnerabilities and Exposures assigned an identifier <a href="https://access.redhat.com/security/cve/CVE-2011-4693">CVE-2011-4693</a> to the following vulnerability: Name: <a href="https://access.redhat.com/security/cve/CVE-2011-4693">CVE-2011-4693</a> URL: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4693">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4693</a> Assigned: 20111207 Reference: <a href="https://lists.immunityinc.com/pipermail/dailydave/2011-December/000402.html">https://lists.immunityinc.com/pipermail/dailydave/2011-December/000402.html</a> Reference: <a href="http://partners.immunityinc.com/movies/VulnDisco-Flash0day-v2.mov">http://partners.immunityinc.com/movies/VulnDisco-Flash0day-v2.mov</a> Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and Mac OS X allows remote attackers to execute arbitrary code via a crafted SWF file, as demonstrated by the first of two vulnerabilities exploited by the Intevydis vd_adobe_fp module in VulnDisco Step Ahead (SA). NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. NOTE: it is unclear whether or not Linux is also affected by this flaw.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player for Internet Explorer 11 | =11.1.102.55 | |
macOS Yosemite | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4693 has been classified as a critical vulnerability due to its potential for allowing remote code execution.
To fix CVE-2011-4693, users should update Adobe Flash Player to the latest version where the vulnerability has been patched.
CVE-2011-4693 specifically affects Adobe Flash Player versions up to 11.1.102.55.
Disabling or uninstalling Adobe Flash Player can act as a temporary workaround for CVE-2011-4693 until a patch is applied.
Exploitation of CVE-2011-4693 could allow an attacker to execute arbitrary code on the affected system, compromising its security.