CVE-2010-1280

HIGH

Adobe Shockwave Player <11.5.7.609 - RCE/DoS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-1280. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit targets a memory corruption vulnerability in Adobe Shockwave Player 11.5.6.606 by crafting a malicious .dir file. The PoC demonstrates arbitrary code execution via a buffer overflow, as evidenced by the crash and register overwrite in the provided debug output.

Description

Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file, related to (1) an erroneous dereference and (2) a certain Shock.dir file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by LiquidWorm · cdoswindows
https://www.exploit-db.com/exploits/12578

This exploit targets a memory corruption vulnerability in Adobe Shockwave Player 11.5.6.606 by crafting a malicious .dir file. The PoC demonstrates arbitrary code execution via a buffer overflow, as evidenced by the crash and register overwrite in the provided debug output.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Adobe Shockwave Player 11.5.6.606 and earlier
No auth needed
Prerequisites: Victim must open a malicious .dir file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38751
Broken Link mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0139.html
Patch, Vendor Advisory x_refsource_confirm
http://www.adobe.com/support/security/bulletins/apsb10-12.html
Broken Link, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/511257/100/0/threaded
Exploit, Third Party Advisory x_refsource_misc
http://www.zeroscience.mk/codes/shockwave_mem.txt
Exploit, Third Party Advisory x_refsource_misc
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4937.php
Broken Link, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1128

Scores

CVSS v3 8.8
EPSS 0.1664
EPSS Percentile 96.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (1)
adobe/shockwave_player < 11.5.7.609
Published May 13, 2010
Tracked Since Feb 18, 2026