CVE-2011-0609

HIGH(7.8)KEVLikely Exploited

Adobe Flash Player Unspecified Vulnerability

Description

CVE-2011-0609 is an unspecified vulnerability in Adobe Flash Player that allows remote attackers to execute arbitrary code or cause a denial of service. The flaw enables an attacker to craft malicious Flash content that, when processed by the Flash Player runtime, leads to code execution in the context of the victim's browser or application. This vulnerability was actively exploited in targeted attacks using Flash content embedded in Microsoft Excel files delivered via email. CISA has added CVE-2011-0609 to its Known Exploited Vulnerabilities catalog, and with an EPSS score of 92.0% (99th percentile), this vulnerability has an extremely high probability of exploitation.

KEV Information

Vendor
Adobe
Product
Flash Player
Date Added
June 8, 2022
Due Date
June 22, 2022
Required Action
The impacted product is end-of-life and should be disconnected if still in use.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9

Affected Products

VendorProductVersion
adobeflash player<= 10.2.154.13; <= 10.1.106.16
adobeacrobat>= 9.0, <= 9.4.2; 10.0; 10.0.1
adobeacrobat reader>= 9.0, <= 9.4.2; 10.0; 10.0.1
adobeair<= 2.5.1
opensuseopensuse11.2; 11.3; 11.4
suselinux enterprise10.0; 11.0
googlechrome< 10.0.648.134

Multiple CVSS Assessments

Source: [email protected](Primary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

CVE-2011-0609 is associated with a memory-related vulnerability in Adobe Flash Player where the runtime fails to properly restrict operations within memory buffer boundaries during content processing. Though the exact technical details were not fully disclosed, the vulnerability allows crafted Flash content to corrupt memory and enable arbitrary code execution.

Learn more: CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer

Impact Analysis

CVE-2011-0609 is remotely exploitable through multiple attack vectors — malicious Flash content can be delivered via web pages, embedded in Office documents (particularly Excel spreadsheets), or served through advertising networks. No authentication is required, and user interaction is limited to opening the document or visiting the page. Successful exploitation results in arbitrary code execution or denial of service, placing confidentiality, integrity, and availability at full risk. The document-based delivery method is particularly dangerous for enterprise environments, as Flash content embedded in Excel files can bypass some security controls. The EPSS score of 92.0% (99th percentile) indicates near-certain exploitation, and the end-of-life status of Flash Player means no further patches will be released.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2011-0609 in the wild by adding it to the Known Exploited Vulnerabilities catalog on June 8, 2022. The EPSS score of 92.0% places this vulnerability in the 99th percentile, indicating an extremely high probability of exploitation. CVE-2011-0609 was exploited in targeted zero-day attacks where malicious Flash (SWF) content was embedded in Microsoft Excel files and delivered via email to specific targets, demonstrating sophisticated targeting capabilities. Adobe Flash Player reached end-of-life on December 31, 2020, and the CISA required action states that the product should be disconnected if still in use. No specific ransomware association has been reported.

Remediation

  1. Remove Adobe Flash Player entirely: Flash Player is end-of-life and should be completely uninstalled from all systems, as directed by the CISA required action.
  2. Block Flash content at the network perimeter and in email: Configure email gateways to strip or quarantine Flash content embedded in Office documents, and block SWF files at web proxies and firewalls.
  3. Disable Flash content in Microsoft Office: Configure Office Trust Center settings to block active content and embedded Flash objects in Excel, Word, and PowerPoint documents.
  4. Audit for systems with residual Flash installations: Conduct enterprise-wide scans to identify any remaining Flash Player installations, particularly on legacy systems that may still process historical documents containing Flash content.
  5. Monitor for Flash-related exploitation indicators: Configure endpoint detection to alert on SWF content extraction from Office documents, unexpected Flash Player process execution, or suspicious network activity following document opening.

Technical Details

CVE-2011-0609 is a vulnerability in Adobe Flash Player that was exploited through a novel delivery mechanism: malicious SWF (Flash) content embedded within Microsoft Excel spreadsheets. When a victim opened the Excel file, the embedded Flash content was automatically rendered by the Flash Player plugin, triggering the vulnerability without any additional user interaction. The vulnerability involves improper handling of memory operations during Flash content processing, classified under CWE-119, which allows an attacker to corrupt memory and redirect execution to arbitrary code. The specific technical mechanism was not fully detailed by Adobe, but the combination of Flash content embedded in Office documents demonstrated a sophisticated attack vector that could bypass security controls focused solely on standalone SWF files or web-based Flash content.

Frequently Asked Questions

Is CVE-2011-0609 being actively exploited?

Yes. CISA has confirmed active exploitation by adding CVE-2011-0609 to the Known Exploited Vulnerabilities catalog. The EPSS score of 92.0% in the 99th percentile indicates near-certain exploitation. The vulnerability was used in targeted zero-day attacks via Flash content embedded in Excel files.

What products are affected by CVE-2011-0609?

CVE-2011-0609 affects Adobe Flash Player, which reached end-of-life on December 31, 2020. The vulnerability was exploited through Flash content embedded in Microsoft Excel files, meaning systems with both Flash Player and Microsoft Office were at risk.

How do I fix CVE-2011-0609?

Completely remove Adobe Flash Player from all systems. Additionally, configure email gateways to block Flash content in Office documents and disable embedded active content in Microsoft Office Trust Center settings.

How severe is CVE-2011-0609?

CVE-2011-0609 is a critically severe vulnerability with an EPSS score in the 99th percentile. It enables remote code execution or denial of service through Flash content that can be delivered via web pages or embedded in Office documents, making it highly effective for targeted attacks.

CVSS Score

7.8
HIGH(7.8)

EPSS Score

EPSS Score66.82%
EPSS Percentile99.2%

Dates

PublishedMarch 15, 2011
Last ModifiedJune 16, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.