CVE-2017-11281 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 33.9% (pctl 98)
Patch early
A public exploit exists.
Description
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 33.88% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-12-01 |
| Last modified | 2026-06-17 |
Affected (10)
| Vendor | Product |
|---|---|
| adobe | flash player |
| apple | macos |
| chrome os | |
| linux | linux kernel |
| microsoft | windows |
| microsoft | windows 10 |
| microsoft | windows 8.1 |
| redhat | enterprise linux desktop |
| redhat | enterprise linux server |
| redhat | enterprise linux workstation |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Adobe Flash - Out-of-Bounds Memory Read in MP4 Parsing | 2017-09-25 |
| exploit-db | Adobe Flash - Out-of-Bounds Write in MP4 Edge Processing | 2017-09-25 |
References
- http://www.securityfocus.com/bid/100710
- http://www.securitytracker.com/id/1039314
- https://access.redhat.com/errata/RHSA-2017:2702
- https://helpx.adobe.com/security/products/flash-player/apsb17-28.html
- https://security.gentoo.org/glsa/201709-16
- https://www.exploit-db.com/exploits/42781/
- https://www.exploit-db.com/exploits/42782/
- https://www.youtube.com/watch?v=CvmnUeza9zw
- http://www.securityfocus.com/bid/100710
- http://www.securitytracker.com/id/1039314
- https://access.redhat.com/errata/RHSA-2017:2702
- https://helpx.adobe.com/security/products/flash-player/apsb17-28.html
- https://security.gentoo.org/glsa/201709-16
- https://www.exploit-db.com/exploits/42781/
- https://www.exploit-db.com/exploits/42782/
- https://www.youtube.com/watch?v=CvmnUeza9zw
→ the Explorer · watch your stack · NVD