10
CVSSv2

CVE-2017-3078

Published: 20/06/2017 Updated: 05/01/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Adobe Flash Player versions 25.0.0.171 and previous versions have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Successful exploitation could lead to arbitrary code execution.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash_player

Vendor Advisories

Synopsis Critical: flash-plugin security update Type/Severity Security Advisory: Critical Topic An update for flash-plugin is now available for Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring Syst ...
Adobe Flash Player versions 2500171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module Successful exploitation could lead to arbitrary code execution ...
A memory corruption vulnerability leading to remote code execution has been found in Adobe Flash Player < 2600126 ...

Exploits

Source: bugschromiumorg/p/project-zero/issues/detail?id=1216 The attached file causes heap corruption in the ATF parser To reproduce the issue, copy atffreeatf and LoadImageswf to a server, and visit 127001/LoadImageswf?img=atffreepng Proof of Concept: githubcom/offensive-security/exploitdb-bin-sploits/raw/mast ...

Github Repositories

CVE-2017-3078 Description On CVE-2017-3078 Adobe has released security updates for Adobe Flash Player for Windows, Macintosh, Linux and Chrome OS These updates address critical vulnerabilities that could potentially allow an attacker to take control of the affected system Description 2 :> Adobe Flash Player versions 2500171 and earlier have an exploitable memory co