CVE-2017-3060: Critical severity Adobe Flash Player Edge vulnerability
Published Apr 12, 2017
·Updated
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the ActionScript2 code parser. Successful exploitation could lead to arbitrary code execution.
Affected Software
21 affected components
Adobe Flash Player Edge<=25.0.0.127
Adobe Flash Player Internet Explorer<=25.0.0.127
Microsoft Windows 10
Microsoft Windows 8.1
Adobe Flash Player Chrome<=25.0.0.127
Apple iOS and macOS
Google Chrome OS
Linux Linux kernel
Microsoft Windows
Adobe Flash Player<=25.0.0.127
All of the following
Any of the following
Adobe Flash Player Edge<=25.0.0.127
Adobe Flash Player Internet Explorer<=25.0.0.127
Any of the following
Microsoft Windows 10
Microsoft Windows 8.1
All of the following
Adobe Flash Player Chrome<=25.0.0.127
Any of the following
Google Chrome OS
Linux Linux kernel
Microsoft Windows
All of the following
Adobe Flash Player<=25.0.0.127
Any of the following
Linux Linux kernel
Microsoft Windows
Event History
Apr 12, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Data Sourced
via NVD·02:59 PM
DescriptionSeverityWeaknessAffected Software
Jun 20, 58461
Event
03:48 PM
Frequently Asked Questions
1
What is the severity of CVE-2017-3060?
CVE-2017-3060 is rated as critical due to the potential for arbitrary code execution.
2
How do I fix CVE-2017-3060?
To fix CVE-2017-3060, upgrade Adobe Flash Player to version 25.0.0.128 or later.
3
Which versions of Adobe Flash Player are affected by CVE-2017-3060?
CVE-2017-3060 affects Adobe Flash Player versions 25.0.0.127 and earlier.
4
What types of attacks can exploit CVE-2017-3060?
CVE-2017-3060 can be exploited through crafted Flash content that triggers memory corruption.
5
What platforms are impacted by CVE-2017-3060?
CVE-2017-3060 impacts Adobe Flash Player used on Windows systems running versions 25.0.0.127 and earlier.