LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2012-0767: Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 8, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 22, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2012-0767 to its Known Exploited Vulnerabilities catalog on Jun 8, 2022, with a federal patch deadline of Jun 22, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Adobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web script or HTML.

CVE-2012-0767 is a cross-site scripting (XSS) vulnerability in Adobe Flash Player. It allows a remote attacker to inject web script or HTML into content handled by the player. Because Flash once ran widely in browsers and embedded applications, unpatched or leftover installations can still expose users and internal systems to script injection that steals session data, alters pages, or delivers further payloads. The product is end-of-life; CISA advises disconnecting it if it remains in use.

How it works

The weakness is CWE-79: improper neutralization of input during web page generation. In this class of flaw, attacker-controlled data is reflected or stored without adequate encoding or validation, so a browser or plugin executes it as script or markup. For Adobe Flash Player, a remote attacker can supply crafted content that the player processes in a way that injects web script or HTML. The injected code then runs in the security context of the affected page or application. Exact trigger conditions and input vectors are not detailed here; confirm mechanics against the vendor advisory. No public facts in this record describe ransomware use of this CVE.

Am I affected? How to find it in your systems

Adobe Flash Player historically appeared as a browser plugin, ActiveX control, or standalone runtime on Windows, macOS, and other desktops, and sometimes inside enterprise kiosks, training tools, or legacy line-of-business apps. Inventory every endpoint and server that might still host the Flash runtime or SWF-handling components.

Confirm exact affected builds and configurations solely against the original vendor advisory; do not rely on version guesses.

How to remediate

The primary remediation is removal. CISA states the impacted product is end-of-life and should be disconnected if still in use. Uninstall Adobe Flash Player completely from every system, revoke any Group Policy or configuration that re-enables it, and block the loading of Flash content at the browser and network layers. Where a vendor security update was once issued for this CVE, apply that update only as an interim step on systems that cannot yet be decommissioned, then proceed to full removal. After uninstall, verify that no Flash libraries or plugins remain and that browsers no longer offer Flash rendering.

For the broader XSS class, ensure any remaining web applications that once relied on Flash now encode output, apply content-security policies, and avoid reflecting untrusted input. Re-scan after changes to confirm the runtime is gone.

If you can't patch immediately

If immediate uninstall is blocked by a legacy dependency, isolate and harden until removal is possible:

These steps only reduce risk; they do not replace disconnection of the end-of-life product.

If your data may have been exposed

Actively exploited vulnerabilities can lead to session theft, account compromise, or broader breaches. If Flash Player was present and reachable, treat the possibility of script injection seriously: rotate credentials that may have been exposed in the browser context, review access logs, and check for unauthorized changes. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora and then take appropriate follow-up steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Flash Player
WeaknessCWE-79
Added to CISA KEVJun 8, 2022
Federal patch deadlineJun 22, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities