CVE-2017-3061 describes a critical memory corruption vulnerability in the SWF parser of Adobe Flash Player versions 25.0.0.127 and earlier, impacting products across Adobe, Apple, Google, Linux, and Microsoft. This vulnerability carries a CVSS score of 9.8, indicating a severe risk where an unauthenticated attacker could achieve arbitrary code execution over a network with low attack complexity. While not listed on CISA's KEV catalog, public exploit code (EDB-42018) exists, and the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 25.0.0.127CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 25.0.0.127CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 25.0.0.127CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 25.0.0.127CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.