Skip to content
COOEY

EXPOSURES › CVE-2011-0611

CVE-2011-0611

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2011-0611 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatchedransomware

Adobe Flash Player's unpatched remote code execution vulnerability (CVE-2011-0611) remains actively exploited in the wild despite the product's end-of-life in 2020.

Adobe Flash Player reached end-of-life in December 2020, yet CVE-2011-0611 remains actively exploited in the wild, allowing remote attackers to execute arbitrary code via crafted content. DIB organizations must ensure Flash is completely removed from all systems, as any residual installation represents a perpetual, unpatched liability that can be weaponized for ransomware or data exfiltration. Immediate remediation requires verifying Flash removal and blocking legacy content delivery.

Shame score — Adobe failed to patch a known critical vulnerability for years after its discovery, and the product's end-of-life compounded the negligence by leaving systems perpetually vulnerable to active exploitation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized