CVE-2012-6270

high

Description

Adobe Shockwave Player through 11.6.8.638 allows remote attackers to trigger installation of a Shockwave Player 10.4.0.025 compatibility feature via a crafted HTML document that references Shockwave content with a certain compatibility parameter, related to a "downgrading" attack.

References

http://www.kb.cert.org/vuls/id/546769

http://www.kb.cert.org/vuls/id/323161

Details

Source: Mitre, NVD

Published: 2012-12-20

Updated: 2017-11-17

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High