First published: Tue May 09 2017(Updated: )
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the BitmapData class. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player | <=25.0.0.163 | |
Apple iOS and macOS | ||
Macromedia Flash Player | <=25.0.0.148 | |
Macromedia Flash Player | <=25.0.0.148 | |
Microsoft Windows 10 | ||
Microsoft Windows 8.1 | ||
Macromedia Flash Player | <=25.0.0.148 | |
Chrome OS | ||
Linux Kernel | ||
Microsoft Windows | ||
Adobe Flash Player | <=25.0.0.148 | |
Red Hat Enterprise Linux | =6.0 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Workstation | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3072 has been classified as a critical vulnerability due to its potential for arbitrary code execution.
To mitigate CVE-2017-3072, users should update Adobe Flash Player to version 25.0.0.163 or later.
CVE-2017-3072 affects Adobe Flash Player versions 25.0.0.148 and earlier.
Exploiting CVE-2017-3072 could allow an attacker to execute arbitrary code on the affected system.
Any user running affected versions of Adobe Flash Player, particularly in web browsers, is at risk for CVE-2017-3072.