First published: Tue Jun 20 2017(Updated: )
Adobe Captivate versions 9 and earlier have a remote code execution vulnerability in the quiz reporting feature that could be abused to read and write arbitrary files to the server.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Captivate | <=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3098 is a critical vulnerability that allows remote code execution through the quiz reporting feature in Adobe Captivate.
To fix CVE-2017-3098, upgrade to a version of Adobe Captivate that is later than version 9.
Exploitation of CVE-2017-3098 can lead to unauthorized reading and writing of arbitrary files on the server.
Adobe Captivate versions 9 and earlier are affected by CVE-2017-3098.
There is no specific workaround for CVE-2017-3098, so it is strongly advised to upgrade to a secure version as soon as possible.