CVE-2017-3074 is a memory corruption vulnerability in Adobe Flash Player versions 25.0.0.148 and earlier, impacting products across Adobe, Apple, Google, Linux, Microsoft, and Red Hat. With a CVSS score of 8.8 (High), it allows for arbitrary code execution through a network-based, low-complexity attack requiring user interaction, leading to high confidentiality, integrity, and availability impacts. While no public exploit code or active exploitation is confirmed, the vulnerability has garnered significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 25.0.0.163CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* | ||
<= 25.0.0.148CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 25.0.0.148CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 25.0.0.148CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 25.0.0.148CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.