CVE-2017-2933
published 2017-01-11CVE-2017-2933: Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture compression. Successful exploitation…
PriorityP266high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
29.91%
98.0th percentile
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture compression. Successful exploitation could lead to arbitrary code execution.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 24.0.0.186 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for Flash Player loading ATF (Adobe Texture Format) files via SWF with query parameters referencing .atf files, which is the attack vector for this heap overflow in ATF thumbnailing. ↗
- →Monitor for exploitation of Adobe Flash Player versions 24.0.0.186 and earlier; the vulnerability is in texture compression (ATF thumbnailing heap overflow) and successful exploitation leads to arbitrary code execution. ↗
- ·The PoC reproduction requires both LoadImage.swf and thumb2.atf to be served together; the heap overflow is triggered specifically through ATF thumbnail processing, not generic SWF loading. ↗
- ·Red Hat has marked flash-plugin on RHEL 5 as 'Will not fix', meaning patching is not available on that platform. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-59jr-cm49-92fm: Adobe Flash Player versions 24
ghsa_unreviewed·2022-05-14
CVE-2017-2933 [CRITICAL] CWE-119 GHSA-59jr-cm49-92fm: Adobe Flash Player versions 24
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture compression. Successful exploitation could lead to arbitrary code execution.
OSV
CVE-2017-2933: Adobe Flash Player versions 24
osv·2017-01-11·CVSS 8.8
CVE-2017-2933 [HIGH] CVE-2017-2933: Adobe Flash Player versions 24
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture compression. Successful exploitation could lead to arbitrary code execution.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB17-02
vendor_redhat·2017-01-10·CVSS 8.8
CVE-2017-2933 [HIGH] flash-plugin: multiple code execution issues fixed in APSB17-02
flash-plugin: multiple code execution issues fixed in APSB17-02
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture compression. Successful exploitation could lead to arbitrary code execution.
Package: flash-plugin (Red Hat Enterprise Linux 5) - Will not fix
No detection rules found.
Zscaler
Zscaler found Adobe Security Vulnerabilities | 01-10-2017
blogs_zscaler
Zscaler found Adobe Security Vulnerabilities | 01-10-2017
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
CVE-2017-2925 CVE-2017-2926 CVE-2017-2927 CVE-2017-2928 CVE-2017-2930 CVE-2017-2931 CVE-2017-2932 CVE-2017-2933 CVE-2017-2934 CVE-2017-2935 CVE-2017-2936 CVE-2017-2937 CVE-2017-2938 flash-plugin: mult
bugzilla·2017-01-10·CVSS 8.8
CVE-2017-2925 [HIGH] CVE-2017-2925 CVE-2017-2926 CVE-2017-2927 CVE-2017-2928 CVE-2017-2930 CVE-2017-2931 CVE-2017-2932 CVE-2017-2933 CVE-2017-2934 CVE-2017-2935 CVE-2017-2936 CVE-2017-2937 CVE-2017-2938 flash-plugin: mult
CVE-2017-2925 CVE-2017-2926 CVE-2017-2927 CVE-2017-2928 CVE-2017-2930 CVE-2017-2931 CVE-2017-2932 CVE-2017-2933 CVE-2017-2934 CVE-2017-2935 CVE-2017-2936 CVE-2017-2937 CVE-2017-2938 flash-plugin: multiple code execution issues fixed in APSB17-02
Adobe Security Bulletin APSB17-02 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB17-02:
These updates resolve a security bypass vulnerability that could lead to information disclosure (CVE-2017-2938).
These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2017-2932, CVE-2017-2936, CVE-2017-2937).
These updates resolve heap buffer overflow vulnerabilities that could lead to code exec
http://rhn.redhat.com/errata/RHSA-2017-0057.htmlhttp://www.securityfocus.com/bid/95347http://www.securitytracker.com/id/1037570https://helpx.adobe.com/security/products/flash-player/apsb17-02.htmlhttps://security.gentoo.org/glsa/201702-20https://www.exploit-db.com/exploits/41610/http://rhn.redhat.com/errata/RHSA-2017-0057.htmlhttp://www.securityfocus.com/bid/95347http://www.securitytracker.com/id/1037570https://helpx.adobe.com/security/products/flash-player/apsb17-02.htmlhttps://security.gentoo.org/glsa/201702-20https://www.exploit-db.com/exploits/41610/
2017-01-11
Published