Use After Free Vulnerability in Adobe Flash Player
CVE-2017-2937
8.8HIGH
Key Information:
- Vendor
- Adobe
- Vendor
- CVE Published:
- 11 January 2017
Summary
Adobe Flash Player, specifically versions 24.0.0.186 and earlier, contains a use after free vulnerability within the ActionScript FileReference class due to improper handling of class inheritance. Attackers can exploit this flaw to execute arbitrary code, potentially compromising the affected system. Users and administrators are advised to update to the latest version to mitigate the risks associated with this vulnerability.
Affected Version(s)
Adobe Flash Player 24.0.0.186 and earlier. Adobe Flash Player 24.0.0.186 and earlier.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved