CVE-2017-11292: Adobe Flash Player Type Confusion Vulnerability
Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.
Other sources
Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.
— NVD
Adobe Security Bulletin APSB17-32 for Adobe Flash Player describes a type confusion flaw that can possibly lead to remote code execution when Flash Player is used to play a specially crafted SWF file.
External References:
https://helpx.adobe.com/security/products/flash-player/apsb17-32.html
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/flash-pluginto a version that resolves this vulnerability.Fixed in 27.0.0.170 - Compensating control
If Adobe Flash Player is still in use, disconnect it because the impacted product is end-of-life.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11292?
CVE-2017-11292 is categorized as critical due to its potential for remote code execution.
How do I fix CVE-2017-11292?
To fix CVE-2017-11292, upgrade Adobe Flash Player to version 27.0.0.170 or later.
What is the impact of CVE-2017-11292?
CVE-2017-11292 allows attackers to execute arbitrary code on the user's system.
Which versions of Adobe Flash Player are affected by CVE-2017-11292?
Versions of Adobe Flash Player prior to 27.0.0.170 are affected by CVE-2017-11292.
Are there any workarounds for CVE-2017-11292?
Disabling Adobe Flash Player in your web browser can mitigate the risk of CVE-2017-11292.