VulnerabilityModified
CVE-2017-2926
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability related to processing of atoms in MP4 files.
HIGH 8.8EPSS 9.90%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.90%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability related to processing of atoms in MP4 files. Successful exploitation could lead to arbitrary code execution.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 9.90% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- adobe/flash player
- Source
- psirt@adobe.com
References
- http://rhn.redhat.com/errata/RHSA-2017-0057.htmlThird Party Advisory
- http://www.securityfocus.com/bid/95350Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037570Broken Link, Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/flash-player/apsb17-02.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/201702-20Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0057.htmlThird Party Advisory
- http://www.securityfocus.com/bid/95350Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037570Broken Link, Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/flash-player/apsb17-02.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/201702-20Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.