First published: Tue Mar 14 2017(Updated: )
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable memory corruption vulnerability in the Primetime TVSDK API functionality related to timeline interactions. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | <=24.0.0.221 | |
Apple iOS and macOS | ||
Chrome OS | ||
Linux Kernel | ||
Microsoft Windows Operating System | ||
Macromedia Flash Player | <=24.0.0.221 | |
Macromedia Flash Player | <=24.0.0.221 | |
Windows 10 | ||
Microsoft Windows | ||
Adobe Flash Player | <=24.0.0.221 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2998 has a high severity rating due to its potential to allow arbitrary code execution.
To fix CVE-2017-2998, update Adobe Flash Player to version 24.0.0.222 or later.
CVE-2017-2998 affects Adobe Flash Player versions 24.0.0.221 and earlier.
Yes, CVE-2017-2998 can be exploited remotely through malicious Flash content.
A temporary workaround for CVE-2017-2998 is to disable Flash content in browsers until an update can be applied.