| Vulnerability Name: | CVE-2011-4693 (CCN-71735) |
| Assigned: | 2011-12-06 |
| Published: | 2011-12-06 |
| Updated: | 2017-09-19 |
| Summary: | Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and Mac OS X allows remote attackers to execute arbitrary code via a crafted SWF file, as demonstrated by the first of two vulnerabilities exploited by the Intevydis vd_adobe_fp module in VulnDisco Step Ahead (SA). Note: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
|
| CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)| Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | | Scope: | Scope (S): Changed
| | Impact Metrics: | Confidentiality (C): High Integrity (I): High Availibility (A): High |
|
| CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 7.5 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:UR)| Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Authentication (Au): None | | Impact Metrics: | Confidentiality (C): Complete Integrity (I): Complete Availibility (A): Complete | 9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 7.5 High (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:UR)| Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): None
| | Impact Metrics: | Confidentiality (C): Complete Integrity (I): Complete Availibility (A): Complete |
|
| Vulnerability Type: | CWE-noinfo
|
| Vulnerability Consequences: | Gain Access |
| References: | Source: MITRE Type: CNA CVE-2011-4693
Source: MISC Type: Exploit http://partners.immunityinc.com/movies/VulnDisco-Flash0day-v2.mov
Source: CCN Type: Dailydave mailing list Flash 0day
Source: CCN Type: Adobe Web site Flash Player
Source: CCN Type: OSVDB ID: 77575 Adobe Flash Player SWF File Handling Unspecified Remote Code Execution (2011-4693)
Source: SECTRACK Type: UNKNOWN 1026392
Source: MISC Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=761216
Source: XF Type: UNKNOWN adobe-flash-swf-file-ce(71735)
Source: MLIST Type: UNKNOWN [dailydave] 20111206 Flash 0day
Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:14405
Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:15703
|
| Vulnerable Configuration: | Configuration 1: cpe:/a:adobe:flash_player:11.1.102.55:*:*:*:*:*:*:*AND cpe:/o:apple:mac_os_x:*:*:*:*:*:*:*:*OR cpe:/o:microsoft:windows:*:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:adobe:flash_player:11.1.102.55:*:*:*:*:*:*:*
Denotes that component is vulnerable |
| Oval Definitions |
| Definition ID | Class | Title | Last Modified |
|---|
| oval:org.mitre.oval:def:14405 | V | Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and Mac OS X allows remote attackers to execute arbitrary code via a crafted SWF file, as demonstrated by the first of two vulnerabilities exploited by the Intevydis vd_adobe_fp module in VulnDisco Step Ahead (SA). NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. | 2015-08-03 | | oval:org.mitre.oval:def:15703 | V | Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and Mac OS X allows remote attackers to execute arbitrary code via a crafted SWF file, as demonstrated by the first of two vulnerabilities exploited by the Intevydis vd_adobe_fp module in VulnDisco Step Ahead (SA). NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. | 2013-02-04 |
|
| BACK |