First published: Tue Jun 13 2017(Updated: )
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability when manipulating the ActionsScript 2 XML class. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/flash-plugin | <26.0.0.126 | 26.0.0.126 |
Adobe Acrobat Reader | <=25.0.0.171 | |
Adobe Acrobat Reader | <=25.0.0.171 | |
Microsoft Windows 10 | ||
Microsoft Windows 8.1 | ||
Adobe Acrobat Reader | <=25.0.0.171 | |
Apple iOS and macOS | ||
Chrome OS | ||
Linux Kernel | ||
Microsoft Windows | ||
Adobe Acrobat Reader | <=25.0.0.171 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3075 has a high severity rating due to its potential for arbitrary code execution.
To mitigate CVE-2017-3075, update Adobe Flash Player to version 26.0.0.126 or later.
CVE-2017-3075 affects Adobe Flash Player versions 25.0.0.171 and earlier.
Exploitation of CVE-2017-3075 can lead to arbitrary code execution, allowing attackers to potentially take control of the affected system.
No, Adobe Flash Player on Windows 10 is not vulnerable if it is updated to the safe version.