Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2017-3106Incorrect Type Conversion or Cast in Adobe Flash Player

Severity
8.8HIGHNVD
EPSS
53.3%
top 2.02%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedAug 11
Latest updateMay 13

Description

Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages5 packages

Also affects: Enterprise Linux 6.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-fvch-gj67-rr73: Adobe Flash Player versions 262022-05-13
OSV
CVE-2017-3106: Adobe Flash Player versions 262017-08-11
CVEList
CVE-2017-3106: Adobe Flash Player versions 262017-08-11

💥Exploits & PoCs

1
Exploit-DB
Adobe Flash - Invoke Accesses Trait Out-of-Bounds2017-08-17

📋Vendor Advisories

1
Red Hat
flash-plugin: Remote Code Execution due to Type Confusion issue fixed in APSB17-232017-08-08

💬Community

1
Bugzilla
CVE-2017-3106 flash-plugin: Remote Code Execution due to Type Confusion issue fixed in APSB17-232017-08-09
CVE-2017-3106 — Incorrect Type Conversion or Cast | cvebase