CVE-2011-0611
Summary
| CVE | CVE-2011-0611 |
|---|---|
| State | PUBLISHED |
| Assigner | adobe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-04-13 14:55:01 UTC |
| Updated | 2026-04-21 20:30:01 UTC |
| Description | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.994100000 probability, percentile 0.999370000 (date 2026-07-22)
CISA KEV: Listed on 2022-03-03; due 2022-03-24; ransomware use Unknown
Problem Types: CWE-843 | n/a | CWE-843 CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
CISA Known Exploited Vulnerability
| Vendor | Adobe |
|---|---|
| Product | Flash Player |
| Name | Adobe Flash Player Remote Code Execution Vulnerability |
| Required Action | The impacted product is end-of-life and should be disconnected if still in use. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2011-0611 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Acrobat Reader | All | All | All | All |
| Application | Adobe | Acrobat Reader | All | All | All | All |
| Application | Adobe | Flash Player | All | All | All | All |
| Application | Adobe | Flash Player | All | All | All | All |
| Operating System | Apple | Mac Os X | - | All | All | All |
| Operating System | Android | - | All | All | All | |
| Operating System | Linux | Linux Kernel | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Operating System | Oracle | Solaris | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | N/a | affected n/a | Not specified |
| ADP | Adobe | Flash Player | affected 10.2.154.27 custom | Not specified |
| ADP | Adobe | Air | affected 2.6.19140 custom | Not specified |
| ADP | Adobe | Reader | affected 9.0 9.4.4 custom | Not specified |
| ADP | Adobe | Reader | affected 10.0 10.0.3 custom | Not specified |
| ADP | Adobe | Acrobat | affected 10.0 10.0.3 custom | Not specified |
| ADP | Adobe | Acrobat | affected 9.0 9.4.4 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link, Vendor Advisory |
| Adobe - Security Advisories: APSA11-02 - Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Broken Link, Vendor Advisory |
| BugiX - Security Research: CVE-2011-0611 Adobe Flash Zero Day embeded in DOC | af854a3a-2127-422b-91ae-364da2661108 | bugix-security.blogspot.com | Exploit |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link, Vendor Advisory |
| CXSecurity - IDS | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | Third Party Advisory |
| Adobe Acrobat/Reader 'Authplay.dll' Flaw Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| Adobe Flash Player Flaw Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| Adobe Flash Player SharedObject Type Confusion Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| Adobe - Security Bulletins: APSB11-07 - Security update available for Adobe Flash Player | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Broken Link, Vendor Advisory |
| Adobe Flash Player 10.2.153.1 SWF Memory Corruption Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| 404 | Flexera Blog | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| Adobe Reader/Acrobat Two Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| Analysis of the CVE-2011-0611 Adobe Flash Player vulnerability exploitation - Microsoft Malware Protection Center - Site Home - TechNet Blogs | af854a3a-2127-422b-91ae-364da2661108 | blogs.technet.com | Not Applicable |
| Chrome Releases: Stable Channel Update | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | Release Notes |
| contagio: Apr. 8 CVE-2011-0611 Flash Player Zero day - SWF in DOC/ XLS - Disentangling Industrial Policy.. | af854a3a-2127-422b-91ae-364da2661108 | contagiodump.blogspot.com | Exploit, Issue Tracking |
| Adobe-Security Bulletins: APSB11-08 - Security update available for Adobe Reader and Acrobat | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Broken Link, Vendor Advisory |
| CXSecurity - IDS | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link, Vendor Advisory |
| US-CERT Vulnerability Note VU#230057 - Adobe Flash Player contains unspecified code execution vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Broken Link, Third Party Advisory, US Government Resource |
| Google Chrome Multiple Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| [security-announce] SUSE Security Announcement: flash-player (SUSE-SA:20 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Patch |
| Adobe Flash Player CVE-2011-0611 'SWF' File Remote Memory Corruption Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2022-03-03T00:00:00.000Z | CVE-2011-0611 added to CISA KEV |
There are currently no legacy QID mappings associated with this CVE.