CVE-2017-2935
published 2017-01-11CVE-2017-2935: Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the Flash Video container file format…
PriorityP267high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
29.91%
98.0th percentile
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the Flash Video container file format. Successful exploitation could lead to arbitrary code execution.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 24.0.0.186 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Heap overflow triggered during AVC header slicing within Flash Video (FLV) container parsing — monitor Flash Player processing of FLV files with malformed AVC headers ↗
- →Exploit delivery involves a SWF file loading an external FLV file via URL parameter — inspect HTTP traffic for SWF files requesting FLV resources via query string parameters (e.g., ?img=*.flv) ↗
- →Vulnerable versions are Adobe Flash Player 24.0.0.186 and earlier — flag or block execution of flash-plugin at or below this version ↗
- ·Red Hat Enterprise Linux 5 will not receive a fix for the flash-plugin package — systems running RHEL 5 with Flash remain permanently exposed ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB17-02
vendor_redhat·2017-01-10·CVSS 8.8
CVE-2017-2935 [HIGH] flash-plugin: multiple code execution issues fixed in APSB17-02
flash-plugin: multiple code execution issues fixed in APSB17-02
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the Flash Video container file format. Successful exploitation could lead to arbitrary code execution.
Package: flash-plugin (Red Hat Enterprise Linux 5) - Will not fix
GHSA
GHSA-2xr7-wx8r-phrv: Adobe Flash Player versions 24
ghsa_unreviewed·2022-05-14
CVE-2017-2935 [CRITICAL] CWE-119 GHSA-2xr7-wx8r-phrv: Adobe Flash Player versions 24
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the Flash Video container file format. Successful exploitation could lead to arbitrary code execution.
OSV
CVE-2017-2935: Adobe Flash Player versions 24
osv·2017-01-11·CVSS 8.8
CVE-2017-2935 [HIGH] CVE-2017-2935: Adobe Flash Player versions 24
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the Flash Video container file format. Successful exploitation could lead to arbitrary code execution.
No detection rules found.
Zscaler
Zscaler found Adobe Security Vulnerabilities | 01-10-2017
blogs_zscaler
Zscaler found Adobe Security Vulnerabilities | 01-10-2017
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
CVE-2017-2925 CVE-2017-2926 CVE-2017-2927 CVE-2017-2928 CVE-2017-2930 CVE-2017-2931 CVE-2017-2932 CVE-2017-2933 CVE-2017-2934 CVE-2017-2935 CVE-2017-2936 CVE-2017-2937 CVE-2017-2938 flash-plugin: mult
bugzilla·2017-01-10·CVSS 8.8
CVE-2017-2925 [HIGH] CVE-2017-2925 CVE-2017-2926 CVE-2017-2927 CVE-2017-2928 CVE-2017-2930 CVE-2017-2931 CVE-2017-2932 CVE-2017-2933 CVE-2017-2934 CVE-2017-2935 CVE-2017-2936 CVE-2017-2937 CVE-2017-2938 flash-plugin: mult
CVE-2017-2925 CVE-2017-2926 CVE-2017-2927 CVE-2017-2928 CVE-2017-2930 CVE-2017-2931 CVE-2017-2932 CVE-2017-2933 CVE-2017-2934 CVE-2017-2935 CVE-2017-2936 CVE-2017-2937 CVE-2017-2938 flash-plugin: multiple code execution issues fixed in APSB17-02
Adobe Security Bulletin APSB17-02 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB17-02:
These updates resolve a security bypass vulnerability that could lead to information disclosure (CVE-2017-2938).
These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2017-2932, CVE-2017-2936, CVE-2017-2937).
These updates resolve heap buffer overflow vulnerabilities that could lead to code exec
http://rhn.redhat.com/errata/RHSA-2017-0057.htmlhttp://www.securityfocus.com/bid/95347http://www.securitytracker.com/id/1037570https://helpx.adobe.com/security/products/flash-player/apsb17-02.htmlhttps://security.gentoo.org/glsa/201702-20https://www.exploit-db.com/exploits/41612/http://rhn.redhat.com/errata/RHSA-2017-0057.htmlhttp://www.securityfocus.com/bid/95347http://www.securitytracker.com/id/1037570https://helpx.adobe.com/security/products/flash-player/apsb17-02.htmlhttps://security.gentoo.org/glsa/201702-20https://www.exploit-db.com/exploits/41612/
2017-01-11
Published