CVE-2017-3003 is a use-after-free vulnerability in Adobe Flash Player versions 24.0.0.221 and earlier, impacting products from Adobe, Apple, Google, Linux, and Microsoft. This vulnerability, stemming from an interaction between the privacy UI and the ActionScript 2 Camera object, carries a high CVSS score of 8.8, indicating a network-based attack with low complexity that requires user interaction and can lead to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation (not in KEV or Hot List), public exploit code is not readily available, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 24.0.0.221CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 24.0.0.221CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 24.0.0.221CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 24.0.0.221CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.