CVE-2017-3085
HIGHAdobe Flash Player < 26.0.0.137 - Security Bypass and Information Disclosure via URL Redirect
Title source: llmDescription
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
References (7)
Core 7
Core References
Broken Link, Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1039088
Third Party Advisory vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/201709-16
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2457
Patch, Vendor Advisory x_refsource_confirm
https://helpx.adobe.com/security/products/flash-player/apsb17-23.html
Third Party Advisory, VDB Entry x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-17-634/
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://blog.bjornweb.nl/2017/08/flash-remote-sandbox-escape-windows-user-credentials-leak/
Broken Link, Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/100191
Scores
CVSS v3
7.4
EPSS
0.0448
EPSS Percentile
90.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Details
CWE
CWE-601
Status
published
Products (6)
adobe/flash_player
< 26.0.0.137 (3 CPE variants)
adobe/flash_player_desktop_runtime
< 26.0.0.137
Adobe Systems Incorporated/Flash Player
26.0.0.137 and earlier.
redhat/enterprise_linux
6.0
redhat/enterprise_linux_desktop
6.0
redhat/enterprise_linux_workstation
6.0
Published
Aug 11, 2017
Tracked Since
Feb 18, 2026