CVE-2017-3078

CRITICAL

Adobe Flash Player < 25.0.0.171 - Memory Corruption

Title source: rule

Description

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Successful exploitation could lead to arbitrary code execution.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/42249
nomisec WRITEUP
by homjxi0e · poc
https://github.com/homjxi0e/CVE-2017-3078

Scores

CVSS v3 9.8
EPSS 0.6999
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (2)
adobe/flash_player < 25.0.0.171 (4 CPE variants)
n/a/Adobe Flash Player 25.0.0.171 and earlier. Adobe Flash Player 25.0.0.171 and earlier.
Published Jun 20, 2017
Tracked Since Feb 18, 2026