First published: Tue Jun 20 2017(Updated: )
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the advertising metadata functionality. Successful exploitation could lead to arbitrary code execution.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player for Internet Explorer 11 | <=25.0.0.171 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3084 is considered critical due to its potential to allow arbitrary code execution.
To fix CVE-2017-3084, users should update Adobe Flash Player to the latest version beyond 25.0.0.171.
CVE-2017-3084 affects Adobe Flash Player versions 25.0.0.171 and earlier on supported platforms.
Yes, CVE-2017-3084 can be exploited remotely due to the nature of the vulnerability in advertising metadata.
CVE-2017-3084 is classified as a use after free vulnerability.