cbcvebase.
CVE-2017-3078
published 2017-06-20

CVE-2017-3078: Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Successful…

PriorityP269critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
30.89%
98.1th percentile
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Successful exploitation could lead to arbitrary code execution.

Affected

1 ranges
VendorProductVersion rangeFixed in
adobeflash_player<= 25.0.0.171

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://127.0.0.1/LoadImage.swf?img=atffree.png
filenameatffree.atf
filenameLoadImage.swf
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/42249.zip
  • Look for SWF files loading ATF-format texture files (e.g. .atf extension) via URL query parameters, which is the delivery mechanism for this exploit (LoadImage.swf?img=atffree.png pattern).
  • The vulnerability is triggered in the Adobe Texture Format (ATF) parser inside Flash Player; heap corruption occurs during ATF file parsing — monitor Flash Player process for heap corruption crashes or abnormal memory allocation patterns when processing ATF assets.
  • Affected versions are Adobe Flash Player 25.0.0.171 and earlier; flag or block execution of Flash Player at or below this version string.
  • ·The reproduction URL uses localhost (127.0.0.1) as the PoC server; in real-world attacks the SWF and ATF payload would be hosted on an attacker-controlled remote server, so detection rules should not be scoped to loopback addresses only.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.