CVE-2011-0609Active Exploitation(adobe / acrobat)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch adobe acrobat systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.

5.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-06-22. The impacted product is end-of-life and should be disconnected if still in use.

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • acrobat
  • acrobat_reader
  • air
  • android

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
acrobatacrobat_readerairandroidchromechrome_osflash_playerlinux_enterpriselinux_kernelmac_os_x

7 versions affected across 14 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-29: 1Active Exploitation · 2026-04-29: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-29: 104-29
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • DFIR Lab@DFIR_Lab
    Active Exploitation

    🚨 HIGH: CVE-2011-0609 | CVSS 7.8 Adobe Flash Player ≤10[.]2[.]154[.]13 (Win/Mac/Linux), Reader/Acrobat 9.x-10.x vulnerable to RCE via crafted .swf content. Actively exploited in wild (March 2011). Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/17Pw7Arz1m

    Post summary

    CVE-2011-0609 enables remote code execution in Adobe Flash Player and Acrobat; it was actively exploited in March 2011 and requires an immediate patch.

    0000044
    9 followersView on X
CPE platform detail21 entries

21 of 21 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeacrobat---
Appadobeacrobat10.0--
Appadobeacrobat10.0.1--
Appadobeacrobat_reader---
Appadobeacrobat_reader10.0--
Appadobeacrobat_reader10.0.1--
Appadobeair---
Appadobeflash_player---
OSapplemac_os_x---
OSapplemacos---
OSgoogleandroid---
Appgooglechrome---
OSgooglechrome_os---
OSlinuxlinux_kernel---
OSmicrosoftwindows---
OSopensuseopensuse11.2--
OSopensuseopensuse11.3--
OSopensuseopensuse11.4--
OSoraclesolaris---
OSsuselinux_enterprise10.0--
OSsuselinux_enterprise11.0--

Explore more