CVE-2017-2930
published 2017-01-11CVE-2017-2930: Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurrency error when manipulating a display…
PriorityP265high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
25.06%
97.7th percentile
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurrency error when manipulating a display list. Successful exploitation could lead to arbitrary code execution.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 24.0.0.186 | — |
Detection & IOCsextracted from sources · hover to see the quote
- ·The vulnerability is triggered by a concurrency error when manipulating a display list — exploitation may be timing-dependent and not reliably reproducible in all environments. ↗
- ·Red Hat Enterprise Linux 5 will not receive a fix for the flash-plugin package — systems running this OS and Flash remain permanently exposed. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m8h4-jcmw-392v: Adobe Flash Player versions 24
ghsa_unreviewed·2022-05-14
CVE-2017-2930 [CRITICAL] CWE-119 GHSA-m8h4-jcmw-392v: Adobe Flash Player versions 24
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurrency error when manipulating a display list. Successful exploitation could lead to arbitrary code execution.
OSV
CVE-2017-2930: Adobe Flash Player versions 24
osv·2017-01-11·CVSS 8.8
CVE-2017-2930 [HIGH] CVE-2017-2930: Adobe Flash Player versions 24
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurrency error when manipulating a display list. Successful exploitation could lead to arbitrary code execution.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB17-02
vendor_redhat·2017-01-10·CVSS 8.8
CVE-2017-2930 [HIGH] flash-plugin: multiple code execution issues fixed in APSB17-02
flash-plugin: multiple code execution issues fixed in APSB17-02
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurrency error when manipulating a display list. Successful exploitation could lead to arbitrary code execution.
Package: flash-plugin (Red Hat Enterprise Linux 5) - Will not fix
No detection rules found.
Exploit-DB
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (1)
exploitdb·2017-01-11·CVSS 8.8
CVE-2017-2930 [HIGH] Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (1)
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (1)
---
Source: https://cosig.gouv.qc.ca/en/cosig-2017-01-en/
#####################################################################################
# Application: Adobe Flash Player
# Platforms: Windows,OSX
# Versions: 24.0.0.186 and earlier
# Author: Francis Provencher of COSIG
# Website: https://cosig.gouv.qc.ca/en/advisory/
# Twitter: @COSIG_
# Date: January 10, 2017
# CVE-2017-2930
# COSIG-2016-35
#####################################################################################
1) Introduction
2) Report Timeline
3) Technical details
4) POC
#####################################################################################
1) Introduction
Adobe Flash Player (labeled Shockwave Flash in Internet
Exploit-DB
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (2)
exploitdb·2017-01-11·CVSS 8.8
CVE-2017-2930 [HIGH] Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (2)
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (2)
---
Source: https://cosig.gouv.qc.ca/en/cosig-2017-01-en/
#####################################################################################
# Application: Adobe Flash Player
# Platforms: Windows,OSX
# Versions: 24.0.0.186 and earlier
# Author: Francis Provencher of COSIG
# Website: https://cosig.gouv.qc.ca/en/advisory/
# Twitter: @COSIG_
# Date: January 10, 2017
# CVE-2017-2930
# COSIG-2016-35
#####################################################################################
1) Introduction
2) Report Timeline
3) Technical details
4) POC
#####################################################################################
1) Introduction
Adobe Flash Player (labeled Shockwave Flash in Internet
http://packetstormsecurity.com/files/140463/Adobe-Flash-24.0.0.186-Code-Execution.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0057.htmlhttp://www.securityfocus.com/bid/95350http://www.securitytracker.com/id/1037570https://cosig.gouv.qc.ca/en/cosig-2017-01-en/https://helpx.adobe.com/security/products/flash-player/apsb17-02.htmlhttps://security.gentoo.org/glsa/201702-20https://www.exploit-db.com/exploits/41008/https://www.exploit-db.com/exploits/41012/http://packetstormsecurity.com/files/140463/Adobe-Flash-24.0.0.186-Code-Execution.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0057.htmlhttp://www.securityfocus.com/bid/95350http://www.securitytracker.com/id/1037570https://cosig.gouv.qc.ca/en/cosig-2017-01-en/https://helpx.adobe.com/security/products/flash-player/apsb17-02.htmlhttps://security.gentoo.org/glsa/201702-20https://www.exploit-db.com/exploits/41008/https://www.exploit-db.com/exploits/41012/
2017-01-11
Published