CVE-2017-2986
HIGHAdobe Flash Player < 24.0.0.194 - Remote Code Execution via FLV Codec Heap Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-2986. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages a heap overflow vulnerability in YUVPlane decoding within Adobe Flash Player. The provided FLV file triggers the overflow when loaded via a crafted SWF file, leading to potential remote code execution.
Description
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the Flash Video (FLV) codec. Successful exploitation could lead to arbitrary code execution.
Exploits (1)
This exploit leverages a heap overflow vulnerability in YUVPlane decoding within Adobe Flash Player. The provided FLV file triggers the overflow when loaded via a crafted SWF file, leading to potential remote code execution.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H