cbcvebase.
CVE-2017-2934
published 2017-01-11

CVE-2017-2934: Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when parsing Adobe Texture Format files. Successful…

PriorityP266high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
29.91%
98.0th percentile
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when parsing Adobe Texture Format files. Successful exploitation could lead to arbitrary code execution.

Affected

1 ranges
VendorProductVersion rangeFixed in
adobeflash_player<= 24.0.0.186

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://127.0.0.1/LoadImage.swf?img=planar1.atf
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/41611.zip
filenameplanar1.atf
filenameLoadImage.swf
  • Trigger is a malformed ATF (Adobe Texture Format) file with a crafted planar block that causes heap corruption during decompression — look for .atf files loaded by Flash (.swf) content
  • Exploit delivery involves a SWF file (LoadImage.swf) loading an external ATF file via query parameter — monitor HTTP requests where a .swf loads a .atf resource
  • Vulnerable component is Adobe Flash Player <= 24.0.0.186 parsing Adobe Texture Format files — flag flash-plugin installations at or below this version
  • ·Red Hat has marked flash-plugin on RHEL 5 as 'Will not fix' — systems on RHEL 5 running flash-plugin remain permanently vulnerable with no vendor patch available

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.