ZeroHour

CVE-2017-11292

KEVmass

Type Confusion in Adobe Flash Player 27 Allows Arbitrary Code Execution

CISA: Adobe Flash Player Type Confusion Vulnerability

CVSS 3.1
8.8 high
EPSS
12%p96
Published
()
KEV added
AI analysis

Adobe Flash Player 27.0.0.159 and earlier contains a flawed bytecode verification procedure (CWE-843, type confusion) that lets an untrusted value be used to compute an array index, corrupting object types in the Flash runtime. The flaw is triggered when a user views attacker-crafted Flash (SWF) content — for example embedded in a malicious document or webpage — since the attack vector is network-based with user interaction required and no privileges needed. Successful exploitation yields arbitrary code execution in the context of the Flash process, typically giving the attacker code execution on the endpoint with the current user's rights. Anyone still running Flash Player 27.0.0.159 or earlier is affected, including the Desktop Runtime and the Flash plugin bundled in Red Hat Enterprise Linux Desktop, Server, and Workstation environments; the product has since reached end-of-life. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-03 (ransomware use unknown), related headlines tie it to the October 2017 BlackOasis APT zero-day attacks, and EPSS assigns an ~12% probability of exploitation in the next 30 days (96th percentile).

What to do: Uninstall or disconnect Adobe Flash Player everywhere it is still present — the product is end-of-life and CISA's required action is to disconnect impacted systems still in use. If Flash must temporarily remain (e.g., Red Hat Enterprise Linux systems using the supplementary Flash plugin or legacy desktops), ensure it runs a release later than 27.0.0.159 and block SWF content in browsers, email, and Office documents. Hunt for residual Flash installs, browser plugins, and embedded .swf content before decommissioning.

Affected
Adobe Flash Player Desktop Runtime27.0.0.159 and earlier
Adobe Flash Player (browser/runtime variants)27.0.0.159 and earlier
Red Hat Enterprise Linux Desktop (with Flash Player plugin)Flash Player 27.0.0.159 and earlier (RHEL release not specified in source data)
Red Hat Enterprise Linux Server (with Flash Player plugin)Flash Player 27.0.0.159 and earlier (RHEL release not specified in source data)
Red Hat Enterprise Linux Workstation (with Flash Player plugin)Flash Player 27.0.0.159 and earlier (RHEL release not specified in source data)
Estimated exposure
mass~1 billion active Flash users at the time of disclosure; today only residual legacy installs remain, plausibly hundreds of thousands to millions of systems — Based on Adobe's publicly reported ~1.1 billion active Flash users in the 2017 timeframe and Flash's bundling with Windows and major browsers, sharply reduced after the product's end-of-life in late 2020, which leaves mainly unmanaged or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.

CISA Known Exploited Vulnerability
Affected
Adobe Flash Player
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
adoberedhat
Products
flash player desktop runtime, flash player, enterprise linux desktop, enterprise linux server, enterprise linux workstation
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news