CVE-2017-3081 is a critical use-after-free vulnerability in Adobe Flash Player versions 25.0.0.171 and earlier, impacting various operating systems including Windows, macOS, and Linux. This flaw, stemming from multiple display object mask manipulations, allows for arbitrary code execution with a CVSS score of 9.8 (CRITICAL), indicating a network-exploitable vulnerability with low attack complexity and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild (KEV list) and no public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability received significant media coverage and community discussion at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 25.0.0.171CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:* | ||
<= 25.0.0.171CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:* | ||
<= 25.0.0.171CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:* | ||
<= 25.0.0.171CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.