CVE-2012-0772
critical
CVSS v3
—
CVSS v2
10.0
VIR risk
10.0
Description
An unspecified ActiveX control in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228, and AIR before 3.2.0.2070, on Windows does not properly perform URL security domain checking, which allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@adobe.com — http://www.adobe.com/support/security/bulletins/apsb12-07.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| adobe | flash_player | {"endIncluding":"10.3.183.16"} | |
| adobe | flash_player | 2 | |
| adobe | flash_player | 3 | |
| adobe | flash_player | 4 | |
| adobe | flash_player | 5 | |
| adobe | flash_player | 6 | |
| adobe | flash_player | 6.0.21.0 | |
| adobe | flash_player | 6.0.79 | |
| adobe | flash_player | 7.0 | |
| adobe | flash_player | 7.0.1 | |
| adobe | flash_player | 7.0.14.0 | |
| adobe | flash_player | 7.0.19.0 | |
| adobe | flash_player | 7.0.24.0 | |
| adobe | flash_player | 7.0.25 | |
| adobe | flash_player | 7.0.53.0 | |
| adobe | flash_player | 7.0.60.0 | |
| adobe | flash_player | 7.0.61.0 | |
| adobe | flash_player | 7.0.63 | |
| adobe | flash_player | 7.0.66.0 | |
| adobe | flash_player | 7.0.67.0 | |
| adobe | flash_player | 7.0.68.0 | |
| adobe | flash_player | 7.0.69.0 | |
| adobe | flash_player | 7.0.70.0 | |
| adobe | flash_player | 7.0.73.0 | |
| adobe | flash_player | 7.1 | |
| adobe | flash_player | 7.1.1 | |
| adobe | flash_player | 7.2 | |
| adobe | flash_player | 8.0 | |
| adobe | flash_player | 8.0.22.0 | |
| adobe | flash_player | 8.0.24.0 | |
| adobe | flash_player | 8.0.33.0 | |
| adobe | flash_player | 8.0.34.0 | |
| adobe | flash_player | 8.0.35.0 | |
| adobe | flash_player | 8.0.39.0 | |
| adobe | flash_player | 8.0.42.0 | |
| adobe | flash_player | 9.0 | |
| adobe | flash_player | 9.0.9.0 | |
| adobe | flash_player | 9.0.16 | |
| adobe | flash_player | 9.0.18d60 | |
| adobe | flash_player | 9.0.20 | |
| adobe | flash_player | 9.0.20.0 | |
| adobe | flash_player | 9.0.28 | |
| adobe | flash_player | 9.0.28.0 | |
| adobe | flash_player | 9.0.31 | |
| adobe | flash_player | 9.0.31.0 | |
| adobe | flash_player | 9.0.45.0 | |
| adobe | flash_player | 9.0.47.0 | |
| adobe | flash_player | 9.0.48.0 | |
| adobe | flash_player | 9.0.112.0 | |
| adobe | flash_player | 9.0.114.0 | |
| adobe | flash_player | 9.0.115.0 | |
| adobe | flash_player | 9.0.124.0 | |
| adobe | flash_player | 9.0.125.0 | |
| adobe | flash_player | 9.0.151.0 | |
| adobe | flash_player | 9.0.152.0 | |
| adobe | flash_player | 9.0.155.0 | |
| adobe | flash_player | 9.0.159.0 | |
| adobe | flash_player | 9.0.246.0 | |
| adobe | flash_player | 9.0.260.0 | |
| adobe | flash_player | 9.0.262.0 | |
| adobe | flash_player | 9.0.277.0 | |
| adobe | flash_player | 9.0.280 | |
| adobe | flash_player | 9.0.283.0 | |
| adobe | flash_player | 9.125.0 | |
| adobe | flash_player | 10 | |
| adobe | flash_player | 10.0.0.584 | |
| adobe | flash_player | 10.0.12.10 | |
| adobe | flash_player | 10.0.12.36 | |
| adobe | flash_player | 10.0.15.3 | |
| adobe | flash_player | 10.0.22.87 | |
| adobe | flash_player | 10.0.32.18 | |
| adobe | flash_player | 10.0.42.34 | |
| adobe | flash_player | 10.0.45.2 | |
| adobe | flash_player | 10.1 | |
| adobe | flash_player | 10.1.52.14.1 | |
| adobe | flash_player | 10.1.52.15 | |
| adobe | flash_player | 10.1.53.64 | |
| adobe | flash_player | 10.1.82.76 | |
| adobe | flash_player | 10.1.85.3 | |
| adobe | flash_player | 10.1.92.8 | |
| adobe | flash_player | 10.1.92.10 | |
| adobe | flash_player | 10.1.95.1 | |
| adobe | flash_player | 10.1.95.2 | |
| adobe | flash_player | 10.1.102.64 | |
| adobe | flash_player | 10.1.105.6 | |
| adobe | flash_player | 10.1.106.16 | |
| adobe | flash_player | 10.2.152 | |
| adobe | flash_player | 10.2.152.26 | |
| adobe | flash_player | 10.2.152.32 | |
| adobe | flash_player | 10.2.152.33 | |
| adobe | flash_player | 10.2.153.1 | |
| adobe | flash_player | 10.2.154.13 | |
| adobe | flash_player | 10.2.154.25 | |
| adobe | flash_player | 10.2.156.12 | |
| adobe | flash_player | 10.2.157.51 | |
| adobe | flash_player | 10.2.159.1 | |
| adobe | flash_player | 10.3.181.14 | |
| adobe | flash_player | 10.3.181.16 | |
| adobe | flash_player | 10.3.181.22 | |
| adobe | flash_player | 10.3.181.26 | |
| adobe | flash_player | 10.3.181.34 | |
| adobe | flash_player | 10.3.183.5 | |
| adobe | flash_player | 10.3.183.7 | |
| adobe | flash_player | 10.3.183.10 | |
| adobe | flash_player | 10.3.183.11 | |
| adobe | flash_player | 10.3.183.15 | |
| adobe | flash_player | 11.0 | |
| adobe | flash_player | 11.0.1.152 | |
| adobe | flash_player | 11.0.1.153 | |
| adobe | flash_player | 11.1 | |
| adobe | flash_player | 11.1.102.55 | |
| adobe | flash_player | 11.1.102.62 | |
| adobe | flash_player | 11.1.102.63 | |
| adobe | adobe_air | {"endIncluding":"3.1.0.488"} | |
| adobe | adobe_air | 1.0 | |
| adobe | adobe_air | 1.0.1 | |
| adobe | adobe_air | 1.1 | |
| adobe | adobe_air | 1.5 | |
| adobe | adobe_air | 1.5.1 | |
| adobe | adobe_air | 1.5.2 | |
| adobe | adobe_air | 1.5.3 | |
| adobe | adobe_air | 1.5.3.9120 | |
| adobe | adobe_air | 2.0.2 | |
| adobe | adobe_air | 2.0.3 | |
| adobe | adobe_air | 2.0.3.13070 | |
| adobe | adobe_air | 2.0.4 | |
| adobe | adobe_air | 2.6 | |
| adobe | adobe_air | 2.7 | |
| adobe | adobe_air | 2.7.0.1948 | |
| adobe | adobe_air | 2.7.0.1953 | |
| adobe | adobe_air | 2.7.1 | |
| adobe | adobe_air | 2.7.1.19610 | |
| adobe | adobe_air | 3.0.0.408 | |
| adobe | adobe_air | 3.1.0.485 | |
References
- http://osvdb.org/80706
- http://secunia.com/advisories/48618
- http://www.adobe.com/support/security/bulletins/apsb12-07.html
- http://www.securitytracker.com/id?1026859
- http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15266
- http://osvdb.org/80706
- http://secunia.com/advisories/48618
- http://www.adobe.com/support/security/bulletins/apsb12-07.html
- http://www.securitytracker.com/id?1026859
- http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15266
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.