CVE-2017-3069 is a critical memory corruption vulnerability in Adobe Flash Player versions 25.0.0.148 and earlier, impacting products across Adobe, Apple, Google, Linux, Microsoft, and Red Hat. This flaw, rated 8.8 HIGH, allows for arbitrary code execution through network-based attacks requiring user interaction, with high impacts on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 25.0.0.163CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 25.0.0.148CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 25.0.0.148CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 25.0.0.148CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 25.0.0.148CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.