EXPOSURES › CVE-2011-0609
CVE-2011-0609
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Flash Player, now end-of-life, contained an unspecified vulnerability allowing remote code execution and denial-of-service attacks, and is actively exploited in the wild.
An unspecified vulnerability in Adobe Flash Player allowed for remote code execution and denial-of-service, and remains unpatched due to the product's end-of-life status. DIB organizations using Flash Player face significant compliance risks under CMMC and NIST 800-171, and must immediately remove all instances. Failure to do so exposes systems to active exploitation and potential data compromise.
Shame score — The continued exploitation of a known vulnerability in a discontinued product demonstrates a failure to maintain a minimum level of security hygiene and poses a significant risk to DIB organizations.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |