CVE-2017-2992 is a critical heap overflow vulnerability in Adobe Flash Player versions 24.0.0.194 and earlier, triggered by parsing a malicious MP4 header, affecting products from Adobe, Apple, Google, Linux, and Microsoft. With a CVSS score of 8.8 (HIGH), it allows for arbitrary code execution with low attack complexity and no user interaction beyond visiting a malicious site. While not on CISA's KEV catalog, public exploit code exists on ExploitDB, and it has garnered some community discussion and media coverage, indicating its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 24.0.0.194CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 24.0.0.194CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 24.0.0.194CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 24.0.0.194CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.