CVE-2017-11290 describes a UI Redress (Clickjacking) vulnerability in Adobe Connect versions 9.6.2 and earlier. This medium-severity flaw (CVSS 6.1) allows an unauthenticated attacker to trick a user into performing unintended actions by overlaying malicious content over legitimate UI elements, potentially leading to limited confidentiality and integrity impacts. While no public exploit code or active exploitation is reported, Adobe has released a fix enabling administrators to protect against such attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.6.2CPE matchmatch criteria | cpe:2.3:a:adobe:connect:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.