CVE-2017-3060 is a critical memory corruption vulnerability in the ActionScript2 code parser of Adobe Flash Player versions 25.0.0.127 and earlier, affecting products from Adobe, Apple, Google, Linux, and Microsoft. With a CVSS score of 9.8, it allows for unauthenticated, remote arbitrary code execution with low attack complexity. While no public exploit intelligence like Metasploit or ExploitDB entries are available, and it's not listed in CISA's KEV catalog, it has garnered some community discussion and media coverage. The vulnerability is not currently considered actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 25.0.0.127CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 25.0.0.127CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 25.0.0.127CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 25.0.0.127CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.