CVE-2017-3083
9.8
CRITICAL · CVSS 3.0 · EPSS 14.4% (pctl 97)
Patch early
EPSS 14.4% — above the 10% action threshold.
Description
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the Primetime SDK functionality related to the profile metadata of the media stream. Successful exploitation could lead to arbitrary code execution.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 14.43% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-416 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-06-20 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| adobe | flash player |
References
- http://www.securityfocus.com/bid/99023
- http://www.securitytracker.com/id/1038655
- https://access.redhat.com/errata/RHSA-2017:1439
- https://helpx.adobe.com/security/products/flash-player/apsb17-17.html
- https://security.gentoo.org/glsa/201707-15
- http://www.securityfocus.com/bid/99023
- http://www.securitytracker.com/id/1038655
- https://access.redhat.com/errata/RHSA-2017:1439
- https://helpx.adobe.com/security/products/flash-player/apsb17-17.html
- https://security.gentoo.org/glsa/201707-15
→ the Explorer · watch your stack · NVD