CVE-2017-3101 describes a clickjacking vulnerability in Adobe Connect versions 9.6.1 and earlier, potentially allowing an attacker to trick users into performing unintended actions. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity that could lead to high integrity impact, though confidentiality and availability are not directly affected. Despite its severity, there is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog. Community discussion and media coverage are present but do not indicate widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.6.1CPE matchmatch criteria | cpe:2.3:a:adobe:connect:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.