First published: Sat Dec 09 2017(Updated: )
An issue was discovered in Adobe Shockwave 12.2.9.199 and earlier. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Shockwave Player | <=12.2.9.199 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11294 is classified as a critical vulnerability due to its potential for arbitrary code execution.
To fix CVE-2017-11294, update Adobe Shockwave to version 12.2.9.199 or later.
CVE-2017-11294 is a memory corruption vulnerability.
Adobe Shockwave versions up to and including 12.2.9.199 are affected by CVE-2017-11294.
Yes, CVE-2017-11294 can potentially be exploited remotely, allowing for arbitrary code execution.