CVE-2017-3098

Severity
9.8CRITICAL
EPSS
11.8%
top 6.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 20
Latest updateMay 17

Description

Adobe Captivate versions 9 and earlier have a remote code execution vulnerability in the quiz reporting feature that could be abused to read and write arbitrary files to the server.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5adobe_captivate_9_and_earlier.Adobe Captivate 9 and earlier.

🔴Vulnerability Details

2
GHSA
GHSA-qhqj-4phh-7v5p: Adobe Captivate versions 9 and earlier have a remote code execution vulnerability in the quiz reporting feature that could be abused to read and write2022-05-17
CVEList
CVE-2017-3098: Adobe Captivate versions 9 and earlier have a remote code execution vulnerability in the quiz reporting feature that could be abused to read and write2017-06-20

💬Community

1
Bugzilla
CVE-2017-11573 fontforge: Buffer over-read in ValidatePostScriptFontName function2017-07-26
CVE-2017-3098 (CRITICAL CVSS 9.8) | Adobe Captivate versions 9 and earl | cvebase.io