cbcvebase.
CVE-2017-2931
published 2017-01-11

CVE-2017-2931: Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability related to the parsing of SWF metadata. Successful…

PriorityP264high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
21.14%
97.3th percentile
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability related to the parsing of SWF metadata. Successful exploitation could lead to arbitrary code execution.

Affected

1 ranges
VendorProductVersion rangeFixed in
adobeflash_player<= 24.0.0.186

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/41608.zip
  • Trigger is a specially crafted SWF file with malicious metadata; inspect SWF files for anomalous or oversized metadata sections that may trigger out-of-bounds reads during parsing.
  • Target Adobe Flash Player versions 24.0.0.186 and earlier; flag or block execution of Flash Player at or below this version string.
  • ·Red Hat Enterprise Linux 5 will not receive a fix for the flash-plugin package; environments running RHEL 5 with Flash remain permanently exposed.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.