CVE-2017-11282 Information
Description
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
http://packetstormsecurity.com/files/144332/Adobe-Flash-appleToRange-Out-Of-Bounds-Read.html http://www.securityfocus.com/bid/100716 http://www.securitytracker.com/id/1039314 https://access.redhat.com/errata/RHSA-2017:2702 https://bugs.chromium.org/p/project-zero/issues/detail?id=1323 https://helpx.adobe.com/security/products/flash-player/apsb17-28.html https://security.gentoo.org/glsa/201709-16 https://www.exploit-db.com/exploits/42783/ https://www.youtube.com/watch?v=6iZnIQbRf5M
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: