PatchSiren cyber security CVE debrief
CVE-2012-0767 Adobe CVE debrief
CVE-2012-0767 is a cross-site scripting vulnerability in Adobe Flash Player that appears in CISA’s Known Exploited Vulnerabilities catalog. The supplied CISA record treats the impacted product as end-of-life and says it should be disconnected if it is still in use. Because this is a known-exploited issue in an EOL product, remediation should focus on removal, isolation, and eliminating any remaining dependency on Flash Player.
- Vendor
- Adobe
- Product
- Flash Player
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2022-06-08
- Original CVE updated
- 2022-06-08
- Advisory published
- 2022-06-08
- Advisory updated
- 2022-06-08
Who should care
Security teams, endpoint and browser administrators, vulnerability management, incident response, and owners of any legacy applications or workflows that still depend on Adobe Flash Player.
Technical summary
The source corpus identifies the issue as an Adobe Flash Player cross-site scripting (XSS) vulnerability and lists it in CISA KEV. No additional technical detail, impact breakdown, or CVSS score is provided in the supplied materials. The most important operational detail in the record is that Flash Player is end-of-life, so CISA’s required action is to disconnect it if it remains deployed.
Defensive priority
High. It is listed in CISA’s Known Exploited Vulnerabilities catalog, and the affected product is end-of-life, which makes continued exposure especially risky.
Recommended defensive actions
- Inventory systems and browsers that still have Adobe Flash Player present or enabled.
- Remove, disable, or disconnect Flash Player wherever it is still in use, consistent with CISA’s guidance for this end-of-life product.
- Identify and migrate any workflows or applications that still depend on Flash content.
- Verify that legacy browser plugins, embedded runtimes, and packaged applications do not reintroduce Flash exposure.
- Prioritize this item in vulnerability and asset remediation tracking because it is listed in CISA KEV.
Evidence notes
Supported by the supplied CISA KEV source item, which names Adobe Flash Player, classifies the issue as a cross-site scripting vulnerability, marks it as KEV, and states that the impacted product is end-of-life and should be disconnected if still in use. The supplied corpus does not include a CVSS score or deeper exploit details.
Sources and references
Verified primary and authoritative sources
-
CVE-2012-0767 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2012-0767
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2012-0767 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2012-0767
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.