CVE-2017-2926 is a critical memory corruption vulnerability in Adobe Flash Player versions 24.0.0.186 and earlier, impacting products across Adobe, Apple, Google, Linux, and Microsoft. This vulnerability, stemming from improper processing of atoms in MP4 files, carries a high CVSS score of 8.8, indicating a severe risk. Successful exploitation, which requires user interaction (UI:R), could lead to arbitrary code execution, resulting in complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 24.0.0.186CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 24.0.0.186CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 24.0.0.186CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 24.0.0.186CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.