EXPOSURES › CVE-2012-1535
CVE-2012-1535
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Flash Player's unpatched arbitrary code execution vulnerability remains a perpetual liability after its December 2020 end-of-life.
Adobe Flash Player reached end-of-life in December 2020 without further security patches, leaving any remaining installations perpetually vulnerable to unpatched exploits. DIB organizations must ensure Flash is completely removed from all systems to avoid exposure to actively exploited vulnerabilities that could lead to remote code execution and data compromise.
Shame score — Adobe failed to patch a critical vulnerability in a product it discontinued, leaving organizations with a perpetual security liability that attackers actively exploit.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |