First published: Fri Jul 14 2017(Updated: )
Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Script 2 BitmapData class. Successful exploitation could lead to memory address disclosure.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player | <=26.0.0.131 | |
macOS Yosemite | ||
Linux Kernel | ||
Microsoft Windows | ||
Adobe Flash Player for Internet Explorer 11 | <=26.0.0.120 | |
Adobe Flash Player for Internet Explorer 11 | <=26.0.0.120 | |
Microsoft Windows 10 | ||
Microsoft Windows 8.1 | ||
Adobe Flash Player for Internet Explorer 11 | <=26.0.0.131 | |
Google Chrome OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3100 is considered a critical vulnerability due to its potential for memory address disclosure through memory corruption.
To fix CVE-2017-3100, update Adobe Flash Player to version 27.0.0.130 or later.
CVE-2017-3100 affects Adobe Flash Player versions 26.0.0.131 and earlier.
CVE-2017-3100 can facilitate attacks that result in memory address disclosure, potentially enabling further exploitation.
No, if you are using Adobe Flash Player version 27.0.0.130 or newer, your system is not vulnerable to CVE-2017-3100.