Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-4694

Overview

Vulnerability Score 9.3 9.3
CVE Id CVE-2011-4694
Last Modified 02 Nov 2013 11:19:16
Published 07 Dec 2011 03:55:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2011-4694

Summary

Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and Mac OS X allows remote attackers to execute arbitrary code via a crafted SWF file, as demonstrated by the second of two vulnerabilities exploited by the Intevydis vd_adobe_fp module in VulnDisco Step Ahead (SA). NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

Vulnerable Systems

Application

  • Adobe Flash Player 11.1.102.55


References

MLIST - [dailydave] 20111206 Flash 0day

MISC - http://partners.immunityinc.com/movies/VulnDisco-Flash0day-v2.mov

MISC - https://bugzilla.redhat.com/show_bug.cgi?id=761223

SECTRACK - 1026392


Last Updated: 27 May 2016 10:57:50