CVE-2017-3077

CRITICAL

Adobe Flash Player <= 25.0.0.171 - Memory Corruption in PNG Image Parser

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-3077. PoCs published by Google Security Research.

AI-analyzed exploit summary This exploit leverages an out-of-bounds read vulnerability in Adobe Flash when decoding a malformed PNG file. The PoC includes a SWF file and a crafted PNG that triggers the issue when accessed via a specific URL.

Description

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser. Successful exploitation could lead to arbitrary code execution.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/42248

This exploit leverages an out-of-bounds read vulnerability in Adobe Flash when decoding a malformed PNG file. The PoC includes a SWF file and a crafted PNG that triggers the issue when accessed via a specific URL.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Adobe Flash Player (versions affected by CVE-2017-3077)
No auth needed
Prerequisites: Web server to host the SWF and PNG files · Victim must visit the crafted URL
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99025
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038655
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/42248/
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1439
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201707-15

Scores

CVSS v3 9.8
EPSS 0.2226
EPSS Percentile 97.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (2)
adobe/flash_player < 25.0.0.171 (4 CPE variants)
n/a/Adobe Flash Player 25.0.0.171 and earlier. Adobe Flash Player 25.0.0.171 and earlier.
Published Jun 20, 2017
Tracked Since Feb 18, 2026