CVE-2012-2040
Description
Untrusted search path vulnerability in the installer in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows local users to gain privileges via a Trojan horse executable file in an unspecified directory.
Risk Information
Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.249
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Upgrade Adobe Air 3.2.0.2070 to latest version | Windows |
| Upgrade Adobe flash player 10.0.0.584 to latest version | Windows |
| Multiple vulnerabilities affected in Adobe AIR 3.2.0.2070 | Windows |
| Multiple vulnerabilities affected in Adobe Flash Player Plugin 11.2.202.235 | Windows |
| Multiple vulnerabilities affected in Adobe Flash Player PPAPI 11.2.202.235 | Windows |
| Multiple Vulnerabilities are affected in Adobe AIR For Mac 3.2.0.2070 | Mac |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-601945 | Update for Adobe AIR For Mac (32.0.0.125) (Deployment-Only) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234