CVE-2017-11292 is a critical type confusion vulnerability in Adobe Flash Player versions 27.0.0.159 and earlier, stemming from flawed bytecode verification that allows untrusted values in array index calculations, impacting products from Adobe, Apple, Google, Linux, Microsoft, and Red Hat. With a CVSS score of 8.8 (HIGH), it is easily exploitable over a network with user interaction, enabling arbitrary code execution with high impact on confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, notably by APT28 and BlackOasis, and has garnered significant community discussion and media coverage, despite a lack of public exploit code on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 27.0.0.159CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 27.0.0.130CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 27.0.0.130CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 27.0.0.159CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.