CVE-2012-1535: Adobe Flash Player Arbitrary Code Execution Vulnerability
Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content.
Other sources
Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted SWF content, as exploited in the wild in August 2012 with SWF content in a Word document.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Flash Playerto a version that resolves this vulnerability.Fixed in 11.3.300.271 - Upgrade
Upgrade
Adobe Flash Playerto a version that resolves this vulnerability.Fixed in 11.2.202.238 - Compensating control
Disconnect the impacted product (Adobe/Macromedia Flash Player) from networks if still in use, as the product is end-of-life.
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1535?
CVE-2012-1535 is classified as critical because it allows remote attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2012-1535?
To address CVE-2012-1535, update Adobe Flash Player to version 11.3.300.271 or later for Windows and Mac OS, and version 11.2.202.238 or later for Linux.
Which versions of Adobe Flash Player are vulnerable to CVE-2012-1535?
Adobe Flash Player versions before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux are vulnerable to CVE-2012-1535.
What types of attacks are possible with CVE-2012-1535?
CVE-2012-1535 allows remote code execution and may lead to denial of service attacks through specially crafted SWF content.
What should users of Adobe Flash Player do regarding CVE-2012-1535?
Users of Adobe Flash Player should immediately upgrade to the latest version to protect against CVE-2012-1535 vulnerabilities.