CVE-2012-2034: Adobe Flash Player Memory Corruption Vulnerability
Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).
Other sources
Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2037.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Flash Player (Windows, Mac OS X)to a version that resolves this vulnerability.Fixed in 10.3.183.20 - Upgrade
Upgrade
Adobe Flash Player (Windows, Mac OS X)to a version that resolves this vulnerability.Fixed in 11.3.300.257 - Upgrade
Upgrade
Adobe Flash Player (Linux)to a version that resolves this vulnerability.Fixed in 10.3.183.20 - Upgrade
Upgrade
Adobe Flash Player (Linux)to a version that resolves this vulnerability.Fixed in 11.2.202.236 - Upgrade
Upgrade
Adobe Flash Player (Android 2.x and 3.x)to a version that resolves this vulnerability.Fixed in 11.1.111.10 - Upgrade
Upgrade
Adobe Flash Player (Android 4.x)to a version that resolves this vulnerability.Fixed in 11.1.115.9 - Upgrade
Upgrade
Adobe AIRto a version that resolves this vulnerability.Fixed in 3.3.0.3610 - Compensating control
Disconnect the impacted product (Adobe Flash Player / Macromedia Flash Player) from the network if still in use, as the product is end-of-life.
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2034?
CVE-2012-2034 has a high severity rating due to its potential for remote code execution and denial-of-service attacks.
How do I fix CVE-2012-2034?
To fix CVE-2012-2034, upgrade Adobe Flash Player to version 11.3.300.257 or later.
Which versions of Adobe Flash Player are affected by CVE-2012-2034?
Adobe Flash Player versions before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X and before 10.3.183.20 and 11.x before 11.2.202.236 on Linux are affected.
Can CVE-2012-2034 lead to data breaches?
Yes, CVE-2012-2034 can potentially lead to data breaches by allowing attackers to execute arbitrary code.
Is CVE-2012-2034 specific to any operating system?
CVE-2012-2034 affects Adobe Flash Player across multiple operating systems, including Windows, Mac OS X, and Linux.