CVE-2012-0754: Adobe Flash Player Memory Corruption Vulnerability
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Other sources
Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Flash Player (Windows, Mac OS X, Linux, Solaris)to a version that resolves this vulnerability.Fixed in 10.3.183.15 - Upgrade
Upgrade
Adobe Flash Player (Windows, Mac OS X, Linux, Solaris)to a version that resolves this vulnerability.Fixed in 11.1.102.62 - Upgrade
Upgrade
Adobe Flash Player (Android 2.x and 3.x)to a version that resolves this vulnerability.Fixed in 11.1.111.6 - Upgrade
Upgrade
Adobe Flash Player (Android 4.x)to a version that resolves this vulnerability.Fixed in 11.1.115.6 - Compensating control
Disconnect the end-of-life Adobe Flash Player from the network / isolate it if it is still in use (the impacted product is end-of-life and should be disconnected).
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0754?
CVE-2012-0754 is classified as a critical vulnerability allowing attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2012-0754?
To fix CVE-2012-0754, update Adobe Flash Player to the latest version, specifically beyond 10.3.183.15 or 11.x beyond 11.1.102.62.
What versions of Adobe Flash Player are affected by CVE-2012-0754?
CVE-2012-0754 affects Adobe Flash Player versions prior to 10.3.183.15 and 11.x prior to 11.1.102.62.
Can CVE-2012-0754 affect my Android device?
Yes, CVE-2012-0754 can affect Android devices running versions below 11.1.111.6 for Android 2.x and 3.x, and below 11.1.115.6 for Android 4.x.
What are the potential consequences of CVE-2012-0754 exploitation?
Exploitation of CVE-2012-0754 can lead to arbitrary code execution or a denial of service, compromising system integrity and availability.