CVE-2017-11282
high-risk
Published 2017-12-01
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
Do I need to act?
!
20.7% chance of exploitation in next 30 days
EPSS score — higher than 79% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
!
1 public exploit available
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (7)
References (18)
Third Party Advisory
http://packetstormsecurity.com/files/144332/Adobe-Flash-appleToRange-Out-Of-Boun...
Third Party Advisory
http://www.securityfocus.com/bid/100716
Third Party Advisory
http://www.securitytracker.com/id/1039314
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2702
Third Party Advisory
https://bugs.chromium.org/p/project-zero/issues/detail?id=1323
Third Party Advisory
https://security.gentoo.org/glsa/201709-16
Third Party Advisory
http://packetstormsecurity.com/files/144332/Adobe-Flash-appleToRange-Out-Of-Boun...
Third Party Advisory
http://www.securityfocus.com/bid/100716
Third Party Advisory
http://www.securitytracker.com/id/1039314
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2702
Third Party Advisory
https://bugs.chromium.org/p/project-zero/issues/detail?id=1323
Third Party Advisory
https://security.gentoo.org/glsa/201709-16
67
/ 100
high-risk
Severity
32/34 · Critical
Exploitability
21/34 · High
Exposure
14/34 · Moderate