CVE-2017-3064 is a critical memory corruption vulnerability in Adobe Flash Player versions 25.0.0.127 and earlier, affecting products from Adobe, Apple, Google, Linux, and Microsoft. This flaw, triggered by parsing a malformed shape outline, carries a high CVSS score of 7.8 due to its potential for arbitrary code execution. While not currently listed in CISA's KEV catalog, an ExploitDB entry exists, and it has garnered some community discussion and media coverage, indicating awareness of the vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 25.0.0.127CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 25.0.0.127CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 25.0.0.127CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 25.0.0.127CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.