PT-2017-1241 · Adobe+3 · Flash Player+3

Published

2017-02-14

·

Updated

2022-11-17

·

CVE-2017-2995

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Flash Player versions 24.0.0.194 and earlier
Description The issue is related to a type confusion vulnerability in the MessageChannel class of Adobe Flash Player. This vulnerability can be exploited to achieve arbitrary code execution. The exploitation is due to memory corruption, allowing a remote attacker to execute arbitrary code.
Recommendations For Adobe Flash Player versions 24.0.0.194 and earlier, update to a version later than 24.0.0.194 to resolve the issue. As a temporary workaround, consider disabling the use of the MessageChannel class until a patch is available. Restrict access to Adobe Flash Player to minimize the risk of exploitation.

Fix

Type Confusion

Incorrect Type Conversion or Cast

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1172
BDU:2017-00355
CVE-2017-2995
MGASA-2017-0075
RHSA-2017:0275
RHSA-2017_0275
SUSE-SU-2017:0523-1
ZDI-17-109

Affected Products

Alt Linux
Flash Player
Red Hat
Suse