cbcvebase.
CVE-2017-2935
published 2017-01-11

CVE-2017-2935: Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the Flash Video container file format…

PriorityP267high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
29.91%
98.0th percentile
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the Flash Video container file format. Successful exploitation could lead to arbitrary code execution.

Affected

1 ranges
VendorProductVersion rangeFixed in
adobeflash_player<= 24.0.0.186

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://127.0.0.1/LoadImage.swf?img=slice.flv
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/41612.zip
filenameLoadImage.swf
filenameslice.flv
  • Heap overflow triggered during AVC header slicing within Flash Video (FLV) container parsing — monitor Flash Player processing of FLV files with malformed AVC headers
  • Exploit delivery involves a SWF file loading an external FLV file via URL parameter — inspect HTTP traffic for SWF files requesting FLV resources via query string parameters (e.g., ?img=*.flv)
  • Vulnerable versions are Adobe Flash Player 24.0.0.186 and earlier — flag or block execution of flash-plugin at or below this version
  • ·Red Hat Enterprise Linux 5 will not receive a fix for the flash-plugin package — systems running RHEL 5 with Flash remain permanently exposed

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.