cbcvebase.
CVE-2017-2992
published 2017-02-15

CVE-2017-2992: Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 header. Successful exploitation could…

PriorityP266high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
32.68%
98.2th percentile
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 header. Successful exploitation could lead to arbitrary code execution.

Affected

2 ranges
VendorProductVersion rangeFixed in
adobeflash_player<= 24.0.0.194
adobeflash_player_desktop_runtime<= 24.0.0.194

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://127.0.0.1/LoadMP4.swf?file=unsigned.mp4
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/41420.zip
filenameLoadMP4.swf
filenameunsigned.mp4
  • Monitor for Flash Player (version <= 24.0.0.194) loading MP4 files via SWF, particularly SWF files passing an MP4 filename as a query parameter (e.g., ?file=*.mp4), which is the PoC delivery pattern for this heap overflow.
  • The vulnerability is triggered during MP4 AMF header parsing in Adobe Flash Player; inspect MP4 files delivered to Flash for malformed or oversized AMF metadata headers.
  • Flag or block flash-plugin package on Red Hat Enterprise Linux 5 systems, as Red Hat has marked this as 'Will not fix', leaving those systems permanently exposed.
  • ·The PoC reproduction URL uses localhost (127.0.0.1); in real-world exploitation the SWF and MP4 would be hosted on an attacker-controlled server, so the IP/domain in the URL will differ.
  • ·Affected versions are Adobe Flash Player 24.0.0.194 and earlier; detections should be scoped to this version ceiling.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.