CVE-2017-3080: Medium severity adobe flash player vulnerability
Adobe Flash Player versions 26.0.0.131 and earlier have a security bypass vulnerability related to the Flash API used by Internet Explorer. Successful exploitation could lead to information disclosure.
Other sources
Adobe Security Bulletin APSB17-21 for Adobe Flash Player describes multiple flaws that can possibly lead to information disclosure when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB17-21:
Security Bypass which can lead to Information Disclosure - CVE-2017-3080 Memory Corruption which can lead to Memory address disclosure - CVE-2017-3100
External References:
https://helpx.adobe.com/security/products/flash-player/apsb17-21.html
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3080?
CVE-2017-3080 is classified as a security bypass vulnerability with potential for information disclosure.
How do I fix CVE-2017-3080?
To fix CVE-2017-3080, upgrade Adobe Flash Player to version 26.0.0.137 or later.
What versions of Adobe Flash Player are affected by CVE-2017-3080?
CVE-2017-3080 affects Adobe Flash Player versions 26.0.0.131 and earlier.
Can CVE-2017-3080 be exploited through Internet Explorer?
Yes, CVE-2017-3080 is specifically related to the Flash API used by Internet Explorer.
Is there a workaround for CVE-2017-3080?
There are no official workarounds for CVE-2017-3080 other than applying the patch by upgrading to the latest version.