CVE-2017-3081: Use After Free
Published Jun 20, 2017
·Updated
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability during internal computation caused by multiple display object mask manipulations. Successful exploitation could lead to arbitrary code execution.
Affected Software
10 affected components
Adobe Flash Player Edge<=25.0.0.171
Adobe Flash Player Internet Explorer<=25.0.0.171
Microsoft Windows 10
Microsoft Windows 8.1
Adobe Flash Player Chrome<=25.0.0.171
Apple iOS and macOS
Google Chrome OS
Linux Linux kernel
Microsoft Windows
Adobe Flash Player<=25.0.0.171
Event History
Jun 20, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-3081?
CVE-2017-3081 has a critical severity rating due to its potential for arbitrary code execution.
2
How do I fix CVE-2017-3081?
To fix CVE-2017-3081, upgrade Adobe Flash Player to version 25.0.0.172 or later.
3
What causes the vulnerability CVE-2017-3081?
CVE-2017-3081 is caused by a use after free vulnerability during internal computation from multiple display object mask manipulations.
4
Which versions of Adobe Flash Player are affected by CVE-2017-3081?
CVE-2017-3081 affects Adobe Flash Player versions 25.0.0.171 and earlier.
5
Can CVE-2017-3081 be exploited remotely?
Yes, CVE-2017-3081 can be exploited remotely, allowing attackers to execute arbitrary code.