CVE-2010-1297
KEVHIGH 9.3EPSS 82.4%
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 82.36% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-06-08
- Published
- 2010-06-08
- Updated
- 2025-10-22
Proof-of-concept exploits (1)
Metasploit modules (1)
ExploitDB entries (4)
- https://www.exploit-db.com/exploits/16687
- https://www.exploit-db.com/exploits/16614
- https://www.exploit-db.com/exploits/14853
- https://www.exploit-db.com/exploits/13787