CVE-2017-3099: Critical severity adobe flash player vulnerability
Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Script 3 raster data model. Successful exploitation could lead to arbitrary code execution.
Other sources
Adobe Security Bulletin APSB17-21 for Adobe Flash Player describes a flaw that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB17-21:
Memory Corruption which can lead to Remote Code Execution - CVE-2017-3099
External References:
https://helpx.adobe.com/security/products/flash-player/apsb17-21.html
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3099?
CVE-2017-3099 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2017-3099?
To mitigate CVE-2017-3099, update Adobe Flash Player to version 26.0.0.137 or later.
Which versions of Adobe Flash Player are affected by CVE-2017-3099?
Adobe Flash Player versions 26.0.0.131 and earlier are affected by CVE-2017-3099.
What can happen if CVE-2017-3099 is exploited?
Exploitation of CVE-2017-3099 can lead to memory corruption and arbitrary code execution.
Are there any platforms immune to CVE-2017-3099?
Yes, recent versions of Adobe Flash Player and other operating systems like Google Chrome OS are not vulnerable to CVE-2017-3099.