Adobe · Flash Player
CVE-2011-0611
Adobe Flash Player Remote Code Execution Vulnerability
CISA KEV record
- CISA date added
- 2022-03-03
- CISA due date
- 2022-03-24
- Known ransomware use
- Unknown
NVD risk context
8.8 HIGH
CVSS is a technical severity score. CISA’s KEV status remains the evidence that this vulnerability is known to be exploited.
Description
Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content.
Required action
The impacted product is end-of-life and should be disconnected if still in use.
NVD reference index
Vendor and remediation references
NVD has tagged these sources as vendor advisories, patches, mitigations, or release notes.
- http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html ↗
- http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00004.html ↗
- http://secunia.com/advisories/44119 ↗
- http://secunia.com/advisories/44141 ↗
- http://secunia.com/advisories/44149 ↗
- http://secunia.com/blog/210/ ↗
- http://www.adobe.com/support/security/advisories/apsa11-02.html ↗
- http://www.adobe.com/support/security/bulletins/apsb11-07.html ↗
- http://www.adobe.com/support/security/bulletins/apsb11-08.html ↗
- http://www.redhat.com/support/errata/RHSA-2011-0451.html ↗
- http://www.vupen.com/english/advisories/2011/0922 ↗
- http://www.vupen.com/english/advisories/2011/0923 ↗
- http://www.vupen.com/english/advisories/2011/0924 ↗
Other NVD references (13)
- http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploitation.aspx ↗
- http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html ↗
- http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html ↗
- http://securityreason.com/securityalert/8204 ↗
- http://securityreason.com/securityalert/8292 ↗
- http://www.exploit-db.com/exploits/17175 ↗
- http://www.kb.cert.org/vuls/id/230057 ↗
- http://www.securityfocus.com/bid/47314 ↗
- http://www.securitytracker.com/id?1025324 ↗
- http://www.securitytracker.com/id?1025325 ↗
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66681 ↗
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14175 ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-0611 ↗
MITRE CWE context
CWE classification
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
View official MITRE CWE details ↗NVD record timing
NVD record timeline
These dates describe NVD’s record, not CISA’s KEV addition or remediation due date.
- NVD published
- Apr 13, 2011, 02:55 PM UTC When NVD first published this CVE record.
- NVD last updated
- Jun 16, 2026, 11:27 PM UTC When NVD last changed its analysis or record data.
Advanced: view the technical CVSS vector
This standardized code is intended for security tools and technical analysts. The plain-language risk summary above explains its main points.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2011-0611