First published: Tue Jun 20 2017(Updated: )
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability during internal computation caused by multiple display object mask manipulations. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | <=25.0.0.171 | |
Adobe Acrobat Reader | <=25.0.0.171 | |
Microsoft Windows 10 | ||
Microsoft Windows 8.1 | ||
Adobe Acrobat Reader | <=25.0.0.171 | |
Apple iOS and macOS | ||
Chrome OS | ||
Linux Kernel | ||
Microsoft Windows | ||
Adobe Acrobat Reader | <=25.0.0.171 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3081 has a critical severity rating due to its potential for arbitrary code execution.
To fix CVE-2017-3081, upgrade Adobe Flash Player to version 25.0.0.172 or later.
CVE-2017-3081 is caused by a use after free vulnerability during internal computation from multiple display object mask manipulations.
CVE-2017-3081 affects Adobe Flash Player versions 25.0.0.171 and earlier.
Yes, CVE-2017-3081 can be exploited remotely, allowing attackers to execute arbitrary code.