VulnerabilityModified
CVE-2017-3068
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced Video Coding engine.
HIGH 8.8EPSS 20.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced Video Coding engine. Successful exploitation could lead to arbitrary code execution.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 20.35% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- adobe/flash player desktop runtime · adobe/flash player · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux workstation
- Source
- psirt@adobe.com
References
- http://www.securityfocus.com/bid/98349Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038427Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1219Third Party Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb17-15.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/201705-12Third Party Advisory
- https://www.exploit-db.com/exploits/42017/Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/98349Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038427Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1219Third Party Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb17-15.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/201705-12Third Party Advisory
- https://www.exploit-db.com/exploits/42017/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.