First published: Tue Mar 14 2017(Updated: )
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable memory corruption vulnerability in the Primetime TVSDK functionality related to hosting playback surface. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | <=24.0.0.221 | |
Apple iOS and macOS | ||
Chrome OS | ||
Linux Kernel | ||
Microsoft Windows Operating System | ||
Macromedia Flash Player | <=24.0.0.221 | |
Macromedia Flash Player | <=24.0.0.221 | |
Windows 10 | ||
Microsoft Windows | ||
Adobe Flash Player | <=24.0.0.221 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2999 has a critical severity rating due to its potential for arbitrary code execution.
To fix CVE-2017-2999, you should update Adobe Flash Player to version 24.0.0.222 or later.
CVE-2017-2999 affects Adobe Flash Player versions 24.0.0.221 and earlier.
CVE-2017-2999 primarily affects Adobe Flash Player, regardless of the operating system it runs on.
Exploitation of CVE-2017-2999 could allow an attacker to execute arbitrary code on the affected system.