Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2017-11281Improper Restriction of Operations within the Bounds of a Memory Buffer in Adobe Flash Player

Severity
9.8CRITICALNVD
EPSS
60.9%
top 1.69%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 1
Latest updateMay 13

Description

Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Patches

🔴Vulnerability Details

3
GHSA
GHSA-94wf-332j-3j5q: Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function2022-05-13
CVEList
CVE-2017-11281: Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function2017-12-01
OSV
CVE-2017-11281: Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function2017-12-01

💥Exploits & PoCs

2
Exploit-DB
Adobe Flash - Out-of-Bounds Write in MP4 Edge Processing2017-09-25
Exploit-DB
Adobe Flash - Out-of-Bounds Memory Read in MP4 Parsing2017-09-25

📋Vendor Advisories

1
Red Hat
flash-plugin: multiple code execution issues fixed in APSB17-282017-09-12

🕵️Threat Intelligence

6
Trendmicro
September Patch Tuesday Fixes MS Office Zero-Day2017-09-13
Trendmicro
September Patch Tuesday Fixes MS Office Zero-Day2017-09-13
Trendmicro
September Patch Tuesday Fixes MS Office Zero-Day2017-09-13
Trendmicro
September Patch Tuesday Fixes MS Office Zero-Day2017-09-13
Trendmicro
September Patch Tuesday Fixes MS Office Zero-Day2017-09-13

💬Community

1
Bugzilla
CVE-2017-11281 CVE-2017-11282 flash-plugin: multiple code execution issues fixed in APSB17-282017-09-13
CVE-2017-11281 — Adobe Flash Player vulnerability | cvebase