CVE-2017-3061

CRITICAL

Adobe Flash Player < 25.0.0.127 - Memory Corruption

Title source: rule

Description

Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser. Successful exploitation could lead to arbitrary code execution.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/42018

Scores

CVSS v3 9.8
EPSS 0.5386
EPSS Percentile 98.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (2)
adobe/flash_player < 25.0.0.127 (4 CPE variants)
n/a/Adobe Flash Player 25.0.0.127 and earlier. Adobe Flash Player 25.0.0.127 and earlier.
Published Apr 12, 2017
Tracked Since Feb 18, 2026