CVE-2010-3654

EXPLOITED IN THE WILD

Adobe Flash Player

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2010-3654 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 3 public exploits from researchers including Abysssec, Metasploit, Unknown, Haifei Li, jduck, including a Metasploit module exploits/windows/fileformat/adobe_flashplayer_button.

AI-analyzed exploit summary This exploit leverages a type confusion vulnerability in Adobe Flash Player to bypass DEP and ASLR on Windows 7. It uses multiple stages to leak memory addresses and execute a ROP payload, ultimately achieving remote code execution.

Description

Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content, as exploited in the wild in October 2010.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Abysssec · textremotewindows
https://www.exploit-db.com/exploits/17187

This exploit leverages a type confusion vulnerability in Adobe Flash Player to bypass DEP and ASLR on Windows 7. It uses multiple stages to leak memory addresses and execute a ROP payload, ultimately achieving remote code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Adobe Flash Player (versions affected by CVE-2010-3654)
No auth needed
Prerequisites: Victim must have vulnerable Adobe Flash Player installed · Victim must visit a malicious webpage or open a malicious SWF file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/16667

This Metasploit module exploits CVE-2010-3654, a vulnerability in Adobe Flash Player (versions 9.x and 10.0) and Adobe Reader/Acrobat. It embeds a malicious SWF file in a PDF, using AcroJS heap spraying and a DEP bypass via BIB.dll to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Adobe Flash Player (9.x, 10.0), Adobe Reader/Acrobat
No auth needed
Prerequisites: Victim must open the malicious PDF file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Unknown, Haifei Li, jduck · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/adobe_flashplayer_button.rb

This Metasploit module exploits CVE-2010-3654, a vulnerability in Adobe Flash Player versions 9.x and 10.0, by embedding a crafted SWF file in a PDF. It uses AcroJS heap spraying and a DEP bypass via BIB.dll to achieve arbitrary code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Adobe Flash Player 9.x, 10.0, Adobe Reader, Acrobat
No auth needed
Prerequisites: Victim must open a malicious PDF file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (37)

Core 37
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4435
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0834.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0934.html
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/298081
Various Sources vendor-advisory x_refsource_turbo
http://www.turbolinux.co.jp/security/2011/TLSA-2011-2j.txt
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0192
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42183
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42030
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0191
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43025
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0344
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43026
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201101-09.xml
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2918
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/3111
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/41917
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201101-08.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1024660
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42926
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2903
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0173
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42401
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1024659
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/44504
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8210
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2906
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0867.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2010-0829.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13294

Scores

EPSS 0.9356
EPSS Percentile 99.8%

Details

VulnCheck KEV 2010-10-29
InTheWild.io 2017-09-19
CWE
CWE-119
Status published
Products (50)
adobe/acrobat 9.0
adobe/acrobat 9.1
adobe/acrobat 9.1.1
adobe/acrobat 9.1.2
adobe/acrobat 9.1.3
adobe/acrobat 9.2
adobe/acrobat 9.3
adobe/acrobat 9.3.1
adobe/acrobat 9.3.2
adobe/acrobat 9.3.3
... and 40 more
Published Oct 29, 2010
Tracked Since Feb 18, 2026