CVE-2017-2933
HIGHAdobe Flash Player < 24.0.0.186 - Remote Code Execution via Texture Compression
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-2933. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages a heap overflow vulnerability in Adobe Flash Player's thumbnailing functionality. It requires a malicious SWF file and an ATF file to trigger the overflow when loaded via a crafted URL.
Description
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture compression. Successful exploitation could lead to arbitrary code execution.
Exploits (1)
This exploit leverages a heap overflow vulnerability in Adobe Flash Player's thumbnailing functionality. It requires a malicious SWF file and an ATF file to trigger the overflow when loaded via a crafted URL.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H