Memory Corruption Vulnerability in Adobe Flash Player by Adobe
CVE-2017-2991

8.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
15 February 2017

Summary

Adobe Flash Player is affected by a memory corruption vulnerability in the h264 codec, related to the decompression process. This flaw allows an attacker to exploit the vulnerability, potentially leading to arbitrary code execution. If successfully exploited, this could compromise the integrity of the system running the affected version of Adobe Flash Player.

Affected Version(s)

Adobe Flash Player 24.0.0.194 and earlier. Adobe Flash Player 24.0.0.194 and earlier.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.