EXPOSURES › CVE-2012-0767
CVE-2012-0767
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Flash Player, now end-of-life, contains a cross-site scripting vulnerability actively exploited in the wild, posing a significant risk to systems still running it despite its discontinuation and lack of updates.
CVE-2012-0767 allows remote attackers to inject scripts and HTML, potentially leading to data theft or system compromise. DIB organizations must immediately identify and remove any remaining Flash Player installations to avoid persistent exploitation and non-compliance with NIST 800-171. Failure to do so creates a perpetual security liability.
Shame score — The continued exploitation of a known vulnerability in a discontinued product demonstrates a failure to maintain a basic security posture and highlights the risks of relying on unsupported software.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web script or HTML.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |