HIGH · 9.3

CVE-2010-2189

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, when used in conjunction with VMWare Tools on a VMWare platform, allows attackers to cause a denial of...

Vulnerability Description

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, when used in conjunction with VMWare Tools on a VMWare platform, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
AdobeFlash Player9.0.16
MacromediaFlash Player5.0
AdobeAir<= 1.5.3.9130

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-2189?

CVE-2010-2189 is a vulnerability with a CVSS score of 9.3 (HIGH). Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, when used in conjunction with VMWare Tools on a VMWare platform, allows attackers to cause a denial of...

How severe is CVE-2010-2189?

CVE-2010-2189 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-2189?

Check the references section above for vendor advisories and patch information. Affected products include: Adobe Flash Player, Macromedia Flash Player, Adobe Air.