CVE-2012-1535: Adobe Flash Player Arbitrary Code Execution Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2022-03-03. EPSS: 70.4% chance of exploitation in the next 30 days.

Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted SWF content, as exploited in the wild in August 2012 with SWF content in a Word document.

Affected products

  • Adobe Flash Player: before 11.3.300.271 (fixed in 11.3.300.271); before 11.2.202.238 (fixed in 11.2.202.238)
  • Opensuse Opensuse: version 11.4 only; version 12.1 only
  • Red Hat Enterprise Linux Desktop: version 5.0 only
  • Red Hat Enterprise Linux Server: version 5.0 only
  • Red Hat Enterprise Linux Workstation: version 5.0 only
  • Suse Linux Enterprise Desktop: version 10 only

Published 2012-08-15. Last modified 2026-06-16.