ZeroHour

CVE-2017-11215

CVSS 3.0
9.8 critical
EPSS
6%p93
Published
()
Modified
Description

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.

Vendors
redhatadobe
Products
enterprise linux desktop, enterprise linux server, enterprise linux workstation, flash player
Weakness
CWE-416
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.