CVE-2017-3085
moderate-risk
Published 2017-08-11
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
Do I need to act?
-
0.81% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.4/10
High
NETWORK
/ LOW complexity
Affected Products (7)
References (14)
Broken Link
http://www.securityfocus.com/bid/100191
Broken Link
http://www.securitytracker.com/id/1039088
Third Party Advisory
http://www.zerodayinitiative.com/advisories/ZDI-17-634/
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2457
Third Party Advisory
https://security.gentoo.org/glsa/201709-16
Broken Link
http://www.securityfocus.com/bid/100191
Broken Link
http://www.securitytracker.com/id/1039088
Third Party Advisory
http://www.zerodayinitiative.com/advisories/ZDI-17-634/
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2457
Third Party Advisory
https://security.gentoo.org/glsa/201709-16
43
/ 100
moderate-risk
Severity
26/34 · High
Exploitability
3/34 · Minimal
Exposure
14/34 · Moderate