Skip to content
COOEY

EXPOSURES › CVE-2012-0767

CVE-2012-0767

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-06-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2012-0767 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Adobe Flash Player, now end-of-life, contains a cross-site scripting vulnerability actively exploited in the wild, posing a significant risk to systems still running it despite its discontinuation and lack of updates.

CVE-2012-0767 allows remote attackers to inject scripts and HTML, potentially leading to data theft or system compromise. DIB organizations must immediately identify and remove any remaining Flash Player installations to avoid persistent exploitation and non-compliance with NIST 800-171. Failure to do so creates a perpetual security liability.

Shame score — The continued exploitation of a known vulnerability in a discontinued product demonstrates a failure to maintain a basic security posture and highlights the risks of relying on unsupported software.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web script or HTML.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized