V
Scaner-VSvulnerability catalog · v4.2
CVE-2017-3061
CVE
HighConfirmedExploit available

Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser. Successful expl…

CVSS
8.8
High
EPSS
0.54
p97
Published
2017-01-01
Updated
2017-01-01
Description

Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser. Successful exploitation could lead to arbitrary code execution.

Tags · CWE
RCEPre-auth
CWE-119
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-14
CAPEC-24
CAPEC-42
CAPEC-44
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-100
CAPEC-123
Affected products
Adobe-flashpluginAdobe-flashpluginAdobe-flashpluginAdobe-flashpluginFlash-pluginFlashplugin-nonfreeFlashplugin-nonfreeFlashplugin-nonfreeFlashplugin-nonfreeFlash_playerFlash_playerFlash_player
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Timeline
2017-01-01
Published
2017-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.539 · p97
Known exploited (KEV)
No
Known exploits — Сканер-ВС
42018
exploitdb · https://www.exploit-db.com/exploits/42018
Enterprise
Affected software
ProductVendorStatus
adobe-flashpluginTracked
adobe-flashpluginTracked
adobe-flashpluginTracked
adobe-flashpluginTracked
flash-pluginTracked
flashplugin-nonfreeTracked
flashplugin-nonfreeTracked
flashplugin-nonfreeTracked
flashplugin-nonfreeTracked
flash_player*Tracked
flash_player*Tracked
flash_player*Tracked
Source databases
CVE
RED
UBU
Related vulnerabilities