CVE-2012-2040: Adobe Air
High severity, CVSS 9.3. EPSS: 4% chance of exploitation in the next 30 days.
Untrusted search path vulnerability in the installer in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows local users to gain privileges via a Trojan horse executable file in an unspecified directory.
Affected products
- Adobe Air: up to and including 3.2.0.2070
- Adobe Flash Player: up to and including 11.2.202.235; up to and including 11.1.115.8; up to and including 11.1.111.9
- Opensuse Opensuse: version 11.4 only; version 12.1 only
- Suse Linux Enterprise Desktop: version 10 only; version 11 only
Published 2012-06-09. Last modified 2026-06-16.