CVE-2017-2982 is a critical use-after-free vulnerability in Adobe Flash Player versions 24.0.0.194 and earlier, affecting products from Adobe, Apple, Google, Linux, and Microsoft. This vulnerability has a CVSS score of 8.8 (High), indicating it can be exploited remotely with low complexity, requiring user interaction, to achieve arbitrary code execution and full compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has received some community discussion and media coverage, suggesting awareness within the security community. Despite its high severity, it is not listed in CISA's KEV catalog and its EPSS score is low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 24.0.0.194CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 24.0.0.194CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 24.0.0.194CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 24.0.0.194CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.