CVE-2017-2934
HIGHAdobe Flash Player <= 24.0.0.186 - Remote Code Execution via Adobe Texture Format Parsing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-2934. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages heap corruption in Adobe Flash Player when decompressing a planar block in an ATF image. The PoC requires hosting two files on a server and visiting a crafted URL to trigger the vulnerability.
Description
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when parsing Adobe Texture Format files. Successful exploitation could lead to arbitrary code execution.
Exploits (1)
This exploit leverages heap corruption in Adobe Flash Player when decompressing a planar block in an ATF image. The PoC requires hosting two files on a server and visiting a crafted URL to trigger the vulnerability.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H