Skip to main content
Mallory
HighCISA KEVExploited in the wildPublic exploit

Remote Code Execution in Adobe Flash Player and Authplay.dll

IdentifiersCVE-2011-0609CWE-119

CVE-2011-0609 is an unspecified memory-corruption vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (AuthPlayLib.bundle) as used by Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X. The flaw can be triggered by crafted Flash content, including malicious .swf files embedded in documents such as Excel spreadsheets or rendered through Adobe Reader/Acrobat components. Adobe and third-party reporting indicate the vulnerability was exploited in the wild as a zero-day in March 2011, including in targeted spear-phishing operations such as the RSA intrusion. Successful exploitation allows attacker-controlled code execution in the context of the affected application; unsuccessful attempts may crash the application and cause denial of service.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

A remote, unauthenticated attacker can induce arbitrary code execution on a vulnerable client system by getting the target to open or render malicious Flash content. In practical intrusion chains, this enabled installation of backdoors and remote access trojans, leading to full compromise of the affected workstation in the security context of the user running Flash, Adobe Reader/Acrobat, or the hosting application. The vulnerability can also be used to cause application crashes, resulting in denial of service.

Mitigation

If you can’t patch tonight, do this now.

Until patching is completed, disable Flash in web browsers and in Adobe Reader/Acrobat, disable 3D & Multimedia support in Reader/Acrobat, remove Flash Player where operationally possible, disable JavaScript in Adobe Reader and Acrobat, prevent automatic opening of PDF files in browsers, and enable DEP on Windows. Restrict delivery of Office/PDF attachments containing embedded Flash content through email and web filtering controls.

Remediation

Patch, then assume compromise.

Apply Adobe's security updates referenced in APSB11-05 and APSB11-06. Upgrade Adobe Flash Player to 10.2.153.1 or later on Windows, Mac, Linux, and Solaris; Flash Player for Android to 10.2.156.12 or later; Adobe Reader X to 10.0.2 or later; and corresponding fixed Adobe Reader/Acrobat releases for affected branches. Google Chrome users should update to 10.0.648.134 or later to obtain the bundled Flash fix. Remove or replace vulnerable Flash-capable components where patching is not feasible.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
AdobeAcrobatapplication
AdobeAcrobat Readerapplication
AdobeAirapplication
AdobeFlash Playerapplication
GoogleChromeapplication
OpensuseOpensuseoperating_system
SuseLinux Enterpriseoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence2

Every observed campaign linking this CVE to a named adversary.

Associated malware2

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.