vendor:
Flash Player
by:
Francis Provencher
8,8
CVSS
HIGH
Remote Code Execution
119
CWE
Product Name: Flash Player
Affected Version From: 24.0.0.186
Affected Version To: Earlier
Patch Exists: YES
Related CWE: CVE-2017-2930
CPE: a:adobe:flash_player
Metasploit:
https://www.rapid7.com/db/vulnerabilities/msft-cve-2017-2930/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2017-2930/, https://www.rapid7.com/db/vulnerabilities/flash_player-cve-2017-2930/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2017-2930/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2017-2930/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2017-2930/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2017-2930/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, OSX
2017
Adobe Flash Player Vulnerability
The vulnerability allows a remote attacker to execute malicious code or access to a part of the dynamically allocated memory using a user interaction visiting a Web page or open a specially crafted SWF file, an attacker is able to execute arbitrary code on the vulnerable system.
Mitigation:
Adobe released a patch (APSB17-02) to address this vulnerability.