CVE-2012-0754
HIGH KEVAdobe Flash Player <10.3.183.15, <11.1.102.62 - Memory Corruption
Title source: llmExploitation Summary
CVE-2012-0754 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 8, 2022.
EIP tracks 2 public exploits from researchers including Metasploit, Alexander Gavrun, sinn3r, juan vazquez, including a Metasploit module exploits/windows/browser/adobe_flash_mp4_cprt.
AI-analyzed exploit summary This is a Metasploit module exploiting CVE-2012-0754, a buffer overflow in Adobe Flash Player's MP4 'cprt' handling. It achieves remote code execution by delivering a malicious MP4 file via a crafted SWF, leveraging ROP chains for different target environments.
Description
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Exploits (2)
This is a Metasploit module exploiting CVE-2012-0754, a buffer overflow in Adobe Flash Player's MP4 'cprt' handling. It achieves remote code execution by delivering a malicious MP4 file via a crafted SWF, leveraging ROP chains for different target environments.
This Metasploit module exploits a memory corruption vulnerability in Adobe Flash Player by delivering a malicious MP4 file, leading to arbitrary code execution. It includes ROP chains for various Windows and IE versions, demonstrating a reliable exploit for CVE-2012-0754.
References (10)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H