CVE-2020-3757: High severity Adobe Flash Player vulnerability
Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
Other sources
Adobe Security Bulletin APSB20-06 for Adobe Flash Player describes a flaw that can possibly lead to arbitrary code execution when Flash Player is used to play a specially crafted SWF file:
Type Confusion -- CVE-2020-3757
External References:
https://helpx.adobe.com/security/products/flash-player/apsb20-06.html
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/flash-pluginto a version that resolves this vulnerability.Fixed in 32.0.0.330 - Upgrade
Upgrade
Adobe Flash Playerto a version that resolves this vulnerability.Fixed in 32.0.0.321 - Upgrade
Upgrade
Adobe Flash Playerto a version that resolves this vulnerability.Fixed in 32.0.0.314 - Upgrade
Upgrade
Adobe Flash Playerto a version that resolves this vulnerability.Fixed in 32.0.0.255 - Compensating control
If Flash Player is used, restrict exposure to untrusted content by limiting where Flash/SWF files can be played until the APSB20-06-referenced update is applied.
Event History
Frequently Asked Questions
What is CVE-2020-3757?
CVE-2020-3757 is a type confusion vulnerability in Adobe Flash Player.
How severe is CVE-2020-3757?
CVE-2020-3757 has a severity score of 8.8, which is considered critical.
Which software versions are affected by CVE-2020-3757?
Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier are affected by CVE-2020-3757.
How can CVE-2020-3757 be exploited?
Successful exploitation of CVE-2020-3757 could lead to arbitrary code execution.
How can I fix CVE-2020-3757?
To fix CVE-2020-3757, update Adobe Flash Player to version 32.0.0.330 or later.