EXPOSURES › CVE-2012-2034
CVE-2012-2034
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Flash Player's unpatched memory corruption flaw allowed remote code execution and was actively exploited in the wild.
An unpatched memory corruption vulnerability in Adobe Flash Player enabled remote code execution and denial-of-service attacks. DIB organizations must ensure all legacy software is patched or disabled, as unpatched CVEs remain a primary compliance failure under NIST 800-171. This flaw was actively exploited in the wild, demonstrating the severe risk of neglecting known vulnerabilities.
Shame score — Adobe failed to patch a known memory corruption vulnerability for years, allowing it to be actively exploited in the wild, which is a severe negligence and avoidable failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |