CVE-2017-2935
HIGHAdobe Flash Player < 24.0.0.186 - Remote Code Execution via Flash Video Container Processing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-2935. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates a heap overflow vulnerability in AVC header slicing within Adobe Flash Player. The PoC requires hosting specific files on a server and accessing a crafted SWF file to trigger the overflow.
Description
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the Flash Video container file format. Successful exploitation could lead to arbitrary code execution.
Exploits (1)
This exploit demonstrates a heap overflow vulnerability in AVC header slicing within Adobe Flash Player. The PoC requires hosting specific files on a server and accessing a crafted SWF file to trigger the overflow.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H