CVE-2017-2988 is a critical memory corruption vulnerability in Adobe Flash Player versions 24.0.0.194 and earlier, affecting products from Adobe, Apple, Google, Linux, and Microsoft. This flaw, stemming from improper garbage collection, allows for arbitrary code execution with a high CVSS score of 8.8, indicating a severe risk. Exploitation requires user interaction (UI:R) but can be achieved remotely (AV:N) with low complexity (AC:L), leading to complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, an ExploitDB entry (EDB-41421) exists, and the vulnerability has garnered significant community discussion and media coverage, suggesting its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 24.0.0.194CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 24.0.0.194CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 24.0.0.194CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 24.0.0.194CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.