CVE-2017-11282 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 34.8% (pctl 98)
Patch early
A public exploit exists.
Description
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 34.85% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-12-01 |
| Last modified | 2026-06-17 |
Affected (10)
| Vendor | Product |
|---|---|
| adobe | flash player |
| apple | macos |
| chrome os | |
| linux | linux kernel |
| microsoft | windows |
| microsoft | windows 10 |
| microsoft | windows 8.1 |
| redhat | enterprise linux desktop |
| redhat | enterprise linux server |
| redhat | enterprise linux workstation |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Adobe Flash - Out-of-Bounds Read in applyToRange | 2017-09-25 |
References
- http://packetstormsecurity.com/files/144332/Adobe-Flash-appleToRange-Out-Of-Bounds-Read.html
- http://www.securityfocus.com/bid/100716
- http://www.securitytracker.com/id/1039314
- https://access.redhat.com/errata/RHSA-2017:2702
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1323
- https://helpx.adobe.com/security/products/flash-player/apsb17-28.html
- https://security.gentoo.org/glsa/201709-16
- https://www.exploit-db.com/exploits/42783/
- https://www.youtube.com/watch?v=6iZnIQbRf5M
- http://packetstormsecurity.com/files/144332/Adobe-Flash-appleToRange-Out-Of-Bounds-Read.html
- http://www.securityfocus.com/bid/100716
- http://www.securitytracker.com/id/1039314
- https://access.redhat.com/errata/RHSA-2017:2702
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1323
- https://helpx.adobe.com/security/products/flash-player/apsb17-28.html
- https://security.gentoo.org/glsa/201709-16
- https://www.exploit-db.com/exploits/42783/
- https://www.youtube.com/watch?v=6iZnIQbRf5M
→ the Explorer · watch your stack · NVD