CVE-2012-1535 is a critical integer overflow vulnerability in Adobe Flash Player, specifically in the parsing of the 'kern' table of embedded OpenType (OTF) font files. The flaw allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by enticing a user to open a crafted SWF file, which can be embedded in documents such as Microsoft Word files or delivered via web browsers. The vulnerability affects Flash Player versions before 11.3.300.271 on Windows and Mac OS X, and before 11.2.202.238 on Linux. Exploitation in the wild was observed in August 2012, with attackers embedding malicious SWF content in Word documents to target unpatched systems.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (adobe_flash_otf_font.rb) that exploits CVE-2012-1535, an integer overflow vulnerability in Adobe Flash Player (before 11.3.300.271) when parsing the 'kern' table of a crafted OTF font. The exploit is delivered via a malicious web server that serves a specially crafted SWF file and font to Internet Explorer users on Windows XP, Vista, or 7. The module uses ROP chains to bypass DEP/ASLR on various target configurations and delivers an arbitrary Metasploit payload (such as a Meterpreter shell) for remote code execution. The main endpoints are dynamically generated HTTP paths serving the SWF and payload, and the exploit loads a SWF file from the Metasploit data directory. The module is operational and weaponized for use within the Metasploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.