CVE-2017-3084 is a critical use-after-free vulnerability in Adobe Flash Player versions 25.0.0.171 and earlier, specifically within its advertising metadata functionality. This flaw carries a CVSS score of 9.8, indicating a critical severity, as it can be exploited remotely with low complexity and no user interaction, potentially leading to arbitrary code execution and full compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, its EPSS score is low, suggesting limited observed exploitation. There is no public exploit code available in Metasploit, Nuclei, or ExploitDB, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 25.0.0.171CPE matchmatch criteria | cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.