CVE-2011-0611Active Exploitation(adobe / acrobat)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch adobe acrobat systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.

5.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-03-24. The impacted product is end-of-life and should be disconnected if still in use.

Weakness type (CWE)
CWE-843

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • acrobat
  • acrobat_reader
  • adobe_air
  • android

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
acrobatacrobat_readeradobe_airandroidchromechrome_osflash_playerlinux_enterprise_desktoplinux_kernelmac_os_x

6 versions affected across 13 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-29: 1Active Exploitation · 2026-04-29: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-29: 104-29
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • DFIR Lab@DFIR_Lab
    Active Exploitation

    🚨 HIGH SEVERITY: CVE-2011-0611 (CVSS 8.8) Adobe Flash Player memory corruption flaw enables remote code execution via crafted SWF files. Affects Flash, AIR, Reader & Acrobat. Exploited in wild via malicious Office docs. Patch immediately! #CVE #PatchNow #ThreatIntel https://t.co/huSJEFTGgx

    Post summary

    CVE-2011-0611 is a high‑severity memory corruption flaw in Adobe Flash that has been actively exploited in the wild via malicious Office documents, and it requires an urgent patch.

    0000034
    9 followersView on X
CPE platform detail16 entries

16 of 16 entries

PartVendorProductVersionTarget SWTarget HW
Appadobeacrobat---
Appadobeacrobat_reader---
Appadobeadobe_air---
Appadobeflash_player---
OSapplemac_os_x---
OSgoogleandroid---
Appgooglechrome---
OSgooglechrome_os---
OSlinuxlinux_kernel---
OSmicrosoftwindows---
OSopensuseopensuse11.2--
OSopensuseopensuse11.3--
OSopensuseopensuse11.4--
OSoraclesolaris---
OSsuselinux_enterprise_desktop10--
OSsuselinux_enterprise_desktop11--

Explore more