CVE-2012-0772
Last modified
CVE-2012-0772 is a vulnerability of currently unknown severity. An unspecified ActiveX control in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228, and AIR before 3.2.0.2070, on Windows does not properly perform URL security domain checking, which allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors.. EPSS estimates a 5.90% chance of exploitation in the next 30 days.
Description
An unspecified ActiveX control in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228, and AIR before 3.2.0.2070, on Windows does not properly perform URL security domain checking, which allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Flash Player | <= 10.3.183.16 |
| Adobe | Flash Player | 2 |
| Adobe | Flash Player | 3 |
| Adobe | Flash Player | 4 |
| Adobe | Flash Player | 5 |
| Adobe | Flash Player | 6 |
| Adobe | Flash Player | 6.0.21.0 |
| Adobe | Flash Player | 6.0.79 |
| Adobe | Flash Player | 7.0 |
| Adobe | Flash Player | 7.0.1 |
| Adobe | Flash Player | 7.0.14.0 |
| Adobe | Flash Player | 7.0.19.0 |
| Adobe | Flash Player | 7.0.24.0 |
| Adobe | Flash Player | 7.0.25 |
| Adobe | Flash Player | 7.0.53.0 |
| Adobe | Flash Player | 7.0.60.0 |
| Adobe | Flash Player | 7.0.61.0 |
| Adobe | Flash Player | 7.0.63 |
| Adobe | Flash Player | 7.0.66.0 |
| Adobe | Flash Player | 7.0.67.0 |
| Adobe | Flash Player | 7.0.68.0 |
| Adobe | Flash Player | 7.0.69.0 |
| Adobe | Flash Player | 7.0.70.0 |
| Adobe | Flash Player | 7.0.73.0 |
| Adobe | Flash Player | 7.1 |
| Adobe | Flash Player | 7.1.1 |
| Adobe | Flash Player | 7.2 |
| Adobe | Flash Player | 8.0 |
| Adobe | Flash Player | 8.0.22.0 |
| Adobe | Flash Player | 8.0.24.0 |
| Adobe | Flash Player | 8.0.33.0 |
| Adobe | Flash Player | 8.0.34.0 |
| Adobe | Flash Player | 8.0.35.0 |
| Adobe | Flash Player | 8.0.39.0 |
| Adobe | Flash Player | 8.0.42.0 |
| Adobe | Flash Player | 9.0 |
| Adobe | Flash Player | 9.0.9.0 |
| Adobe | Flash Player | 9.0.16 |
| Adobe | Flash Player | 9.0.18d60 |
| Adobe | Flash Player | 9.0.20 |
| Adobe | Flash Player | 9.0.20.0 |
| Adobe | Flash Player | 9.0.28 |
| Adobe | Flash Player | 9.0.28.0 |
| Adobe | Flash Player | 9.0.31 |
| Adobe | Flash Player | 9.0.31.0 |
| Adobe | Flash Player | 9.0.45.0 |
| Adobe | Flash Player | 9.0.47.0 |
| Adobe | Flash Player | 9.0.48.0 |
| Adobe | Flash Player | 9.0.112.0 |
| Adobe | Flash Player | 9.0.114.0 |
Showing 50 of 134 affected configurations. See NVD for the full list.
References
- http://www.adobe.com/support/security/bulletins/apsb12-07.htmlPatch, Vendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb12-07.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-0772?
How severe is CVE-2012-0772?
How do I fix CVE-2012-0772?
Are you affected by CVE-2012-0772?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
