First published: Wed Jan 11 2017(Updated: )
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript FileReference class, when using class inheritance. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | <=24.0.0.186 | |
Apple iOS and macOS | ||
Chrome OS | ||
Linux Kernel | ||
Microsoft Windows Operating System | ||
Macromedia Flash Player | <=24.0.0.186 | |
Macromedia Flash Player | <=24.0.0.186 | |
Windows 10 | ||
Microsoft Windows | ||
Macromedia Flash Player | <=24.0.0.186 | |
All of | ||
Macromedia Flash Player | <=24.0.0.186 | |
Any of | ||
Apple iOS and macOS | ||
Chrome OS | ||
Linux Kernel | ||
Microsoft Windows Operating System | ||
All of | ||
Any of | ||
Macromedia Flash Player | <=24.0.0.186 | |
Macromedia Flash Player | <=24.0.0.186 | |
Any of | ||
Windows 10 | ||
Microsoft Windows | ||
All of | ||
Macromedia Flash Player | <=24.0.0.186 | |
Any of | ||
Apple iOS and macOS | ||
Linux Kernel | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2937 is considered a critical vulnerability due to its potential for arbitrary code execution.
To fix CVE-2017-2937, update Adobe Flash Player to version 24.0.0.187 or later.
Adobe Flash Player versions 24.0.0.186 and earlier are affected by CVE-2017-2937.
Exploitation of CVE-2017-2937 could lead to arbitrary code execution on the affected system.
Yes, CVE-2017-2937 specifically impacts Adobe Flash Player and does not affect other software.