CVE-2017-11292
KEVmassType Confusion in Adobe Flash Player 27 Allows Arbitrary Code Execution
CISA: Adobe Flash Player Type Confusion Vulnerability
Adobe Flash Player 27.0.0.159 and earlier contains a flawed bytecode verification procedure (CWE-843, type confusion) that lets an untrusted value be used to compute an array index, corrupting object types in the Flash runtime. The flaw is triggered when a user views attacker-crafted Flash (SWF) content — for example embedded in a malicious document or webpage — since the attack vector is network-based with user interaction required and no privileges needed. Successful exploitation yields arbitrary code execution in the context of the Flash process, typically giving the attacker code execution on the endpoint with the current user's rights. Anyone still running Flash Player 27.0.0.159 or earlier is affected, including the Desktop Runtime and the Flash plugin bundled in Red Hat Enterprise Linux Desktop, Server, and Workstation environments; the product has since reached end-of-life. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-03 (ransomware use unknown), related headlines tie it to the October 2017 BlackOasis APT zero-day attacks, and EPSS assigns an ~12% probability of exploitation in the next 30 days (96th percentile).
What to do: Uninstall or disconnect Adobe Flash Player everywhere it is still present — the product is end-of-life and CISA's required action is to disconnect impacted systems still in use. If Flash must temporarily remain (e.g., Red Hat Enterprise Linux systems using the supplementary Flash plugin or legacy desktops), ensure it runs a release later than 27.0.0.159 and block SWF content in browsers, email, and Office documents. Hunt for residual Flash installs, browser plugins, and embedded .swf content before decommissioning.
| Adobe Flash Player Desktop Runtime | 27.0.0.159 and earlier |
| Adobe Flash Player (browser/runtime variants) | 27.0.0.159 and earlier |
| Red Hat Enterprise Linux Desktop (with Flash Player plugin) | Flash Player 27.0.0.159 and earlier (RHEL release not specified in source data) |
| Red Hat Enterprise Linux Server (with Flash Player plugin) | Flash Player 27.0.0.159 and earlier (RHEL release not specified in source data) |
| Red Hat Enterprise Linux Workstation (with Flash Player plugin) | Flash Player 27.0.0.159 and earlier (RHEL release not specified in source data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.
- Affected
- Adobe Flash Player
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown