Skip to main content
Mallory
HighCISA KEVExploited in the wildPublic exploit

Adobe Flash Player and Authplay.dll type confusion remote code execution

IdentifiersCVE-2011-0611CWE-843· Access of Resource Using…

CVE-2011-0611 is a client-side memory corruption vulnerability in Adobe Flash Player and in the Authplay.dll/AuthPlayLib.bundle component used by Adobe Reader and Acrobat to process embedded Flash content. Affected products include Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris; 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and vulnerable Reader/Acrobat versions that ship the Authplay component. The issue was described as involving a size inconsistency in a group of included constants and object type confusion in crafted Flash content, including ActionScript that adds custom functions to prototypes and uses Date objects. By supplying a malicious SWF directly or embedding it in a document such as a Microsoft Office file, a remote attacker can trigger memory corruption leading to application crash or arbitrary code execution. The vulnerability was actively exploited in the wild in April 2011 and was incorporated into exploit kits.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can allow remote, unauthenticated arbitrary code execution in the context of the user running the vulnerable application. In practical terms this can result in full compromise of the affected workstation, installation of malware, persistence, credential theft, and follow-on lateral movement subject to the privileges of the compromised user. Where code execution is not achieved, exploitation may still cause denial of service via application crash.

Mitigation

If you can’t patch tonight, do this now.

Apply vendor patches as soon as possible. Until patching is complete, disable Flash in browsers and in Adobe Reader/Acrobat where feasible; remove or rename vulnerable components such as authplay.dll to disable Flash handling in Reader/Acrobat; consider uninstalling Flash Player if not operationally required; use EMET or equivalent exploit mitigations; disable JavaScript in Reader/Acrobat to reduce attack surface; prevent PDFs from opening automatically in browsers; and ensure DEP is enabled on Windows systems.

Remediation

Patch, then assume compromise.

Upgrade affected software to fixed versions. The provided advisory indicates upgrading Adobe Flash Player to 10.2.159.1 or later, Adobe Reader 9.x to 9.4.4, Adobe Reader X to 10.0.3, and applying the latest available Adobe Acrobat updates. Also update Adobe AIR to a non-vulnerable release. Remove or disable vulnerable plugin components where updates cannot be applied immediately.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.

VALID 0 / 1 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
AdobeAcrobatapplication
AdobeAcrobat Readerapplication
AdobeAdobe Airapplication
AdobeAirapplication
AdobeFlash Playerapplication
AdobeReaderapplication
GoogleChromeapplication
OpensuseOpensuseoperating_system
SuseLinux Enterprise Desktopoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence6

Every observed campaign linking this CVE to a named adversary.

Associated malware2

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.