CVE-2012-6270: Critical severity adobe shockwave player vulnerability
Adobe Shockwave Player through 11.6.8.638 allows remote attackers to trigger installation of a Shockwave Player 10.4.0.025 compatibility feature via a crafted HTML document that references Shockwave content with a certain compatibility parameter, related to a "downgrading" attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6270?
The severity of CVE-2012-6270 is classified as critical due to its potential to enable remote attacks.
How do I fix CVE-2012-6270?
To fix CVE-2012-6270, users should update Adobe Shockwave Player to the latest version available beyond 11.6.8.638.
Who is affected by CVE-2012-6270?
CVE-2012-6270 affects all versions of Adobe Shockwave Player up to and including 11.6.8.638.
What kind of attack is possible with CVE-2012-6270?
CVE-2012-6270 enables a 'downgrading' attack, allowing attackers to install an older compatibility feature of Shockwave Player.
Is there a workaround for CVE-2012-6270?
Currently, the best workaround for CVE-2012-6270 is to uninstall Adobe Shockwave Player if it is not needed.