CVE-2017-11292
Adobe Flash Player Type Confusion Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
YesDecision
Descriptions
Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.
Adobe Flash Player en sus versiones 27.0.0.159 y anteriores tiene un procedimiento de verificación de código de bytes con errores, lo que permite que un valor que no es de confianza se emplee en el cálculo de un índice de arrays. Esto puede llevar a una confusión de tipos, y la explotación con éxito podría desembocar en la ejecución de código arbitrario.
Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-07-13 CVE Reserved
- 2017-10-17 CVE Published
- 2022-03-03 Exploited in Wild
- 2022-03-24 KEV Due Date
- 2024-08-05 CVE Updated
- 2024-08-11 EPSS Updated
- ---------- First Exploit
CWE
- CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/101286 | Broken Link | |
http://www.securitytracker.com/id/1039582 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/flash-player/apsb17-32.html | 2023-01-27 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2017:2899 | 2023-01-27 | |
https://security.gentoo.org/glsa/201710-22 | 2023-01-27 | |
https://access.redhat.com/security/cve/CVE-2017-11292 | 2017-10-17 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1502726 | 2017-10-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Flash Player Desktop Runtime Search vendor "Adobe" for product "Flash Player Desktop Runtime" | <= 27.0.0.159 Search vendor "Adobe" for product "Flash Player Desktop Runtime" and version " <= 27.0.0.159" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Desktop Runtime Search vendor "Adobe" for product "Flash Player Desktop Runtime" | <= 27.0.0.159 Search vendor "Adobe" for product "Flash Player Desktop Runtime" and version " <= 27.0.0.159" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Desktop Runtime Search vendor "Adobe" for product "Flash Player Desktop Runtime" | <= 27.0.0.159 Search vendor "Adobe" for product "Flash Player Desktop Runtime" and version " <= 27.0.0.159" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 27.0.0.130 Search vendor "Adobe" for product "Flash Player" and version " <= 27.0.0.130" | edge |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows 10 Search vendor "Microsoft" for product "Windows 10" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 27.0.0.130 Search vendor "Adobe" for product "Flash Player" and version " <= 27.0.0.130" | edge |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows 8.1 Search vendor "Microsoft" for product "Windows 8.1" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 27.0.0.130 Search vendor "Adobe" for product "Flash Player" and version " <= 27.0.0.130" | internet_explorer |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows 10 Search vendor "Microsoft" for product "Windows 10" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 27.0.0.130 Search vendor "Adobe" for product "Flash Player" and version " <= 27.0.0.130" | internet_explorer |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows 8.1 Search vendor "Microsoft" for product "Windows 8.1" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 27.0.0.159 Search vendor "Adobe" for product "Flash Player" and version " <= 27.0.0.159" | chrome |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 27.0.0.159 Search vendor "Adobe" for product "Flash Player" and version " <= 27.0.0.159" | chrome |
Affected
| in | Google Search vendor "Google" | Chrome Os Search vendor "Google" for product "Chrome Os" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 27.0.0.159 Search vendor "Adobe" for product "Flash Player" and version " <= 27.0.0.159" | chrome |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | <= 27.0.0.159 Search vendor "Adobe" for product "Flash Player" and version " <= 27.0.0.159" | chrome |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Search vendor "Redhat" for product "Enterprise Linux Server" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Server" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Workstation Search vendor "Redhat" for product "Enterprise Linux Workstation" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Workstation" and version "6.0" | - |
Affected
|