CVE-2017-3085

HIGH

Adobe Flash Player < 26.0.0.137 - Security Bypass and Information Disclosure via URL Redirect

Title source: llm
STIX 2.1

Description

Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.

References (7)

Core 7
Core References
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1039088
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201709-16
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2457
Third Party Advisory, VDB Entry x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-17-634/
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://blog.bjornweb.nl/2017/08/flash-remote-sandbox-escape-windows-user-credentials-leak/
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/100191

Scores

CVSS v3 7.4
EPSS 0.0448
EPSS Percentile 90.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

Details

CWE
CWE-601
Status published
Products (6)
adobe/flash_player < 26.0.0.137 (3 CPE variants)
adobe/flash_player_desktop_runtime < 26.0.0.137
Adobe Systems Incorporated/Flash Player 26.0.0.137 and earlier.
redhat/enterprise_linux 6.0
redhat/enterprise_linux_desktop 6.0
redhat/enterprise_linux_workstation 6.0
Published Aug 11, 2017
Tracked Since Feb 18, 2026