CVE-2017-3077

CRITICAL

Adobe Flash Player < 25.0.0.171 - Memory Corruption

Title source: rule

Description

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser. Successful exploitation could lead to arbitrary code execution.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/42248

Scores

CVSS v3 9.8
EPSS 0.5386
EPSS Percentile 98.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (2)
adobe/flash_player < 25.0.0.171 (4 CPE variants)
n/a/Adobe Flash Player 25.0.0.171 and earlier. Adobe Flash Player 25.0.0.171 and earlier.
Published Jun 20, 2017
Tracked Since Feb 18, 2026