peter bassill · operator
$ cve CVE-2017-11225 JSON

CVE-2017-11225

9.8
CRITICAL · CVSS 3.0 · EPSS 6.1% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK metadata functionality. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.08% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-416
On CISA KEVno
Public exploitnone known
Published2017-12-09
Last modified2026-06-17

Affected (10)

VendorProduct
adobeflash player
applemacos
googlechrome os
linuxlinux kernel
microsoftwindows
microsoftwindows 10
microsoftwindows 8.1
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux workstation

References

→ the Explorer  ·  watch your stack  ·  NVD