CVE-2017-11225

HIGH

Description

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK metadata functionality. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.

References

http://www.securityfocus.com/bid/101837

http://www.securitytracker.com/id/1039778

https://access.redhat.com/errata/RHSA-2017:3222

https://helpx.adobe.com/security/products/flash-player/apsb17-33.html

https://security.gentoo.org/glsa/201711-13

Details

Source: MITRE

Published: 2017-12-09

Updated: 2017-12-21

Type: CWE-416

Risk Information

CVSS v2.0

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH

CVSS v3.0

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 3.9

Severity: CRITICAL

Tenable Plugins

View all (11 total)

IDNameProductFamilySeverity
700427Flash Player < 27.0.0.187 Multiple Vulnerabilities (APSB17-33)Nessus Network MonitorWeb Clients
critical
108436openSUSE Security Update : Chromium (openSUSE-2018-264)NessusSuSE Local Security Checks
critical
107243FreeBSD : chromium -- vulnerability (555af074-22b9-11e8-9799-54ee754af08e)NessusFreeBSD Local Security Checks
critical
107221Google Chrome < 65.0.3325.146 Multiple Vulnerabilities (macOS)NessusMacOS X Local Security Checks
critical
107220Google Chrome < 65.0.3325.146 Multiple VulnerabilitiesNessusWindows
critical
104694GLSA-201711-13 : Adobe Flash Player: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
104647FreeBSD : Flash Player -- multiple vulnerabilities (52f10525-caff-11e7-b590-6451062f0f7a)NessusFreeBSD Local Security Checks
critical
104622RHEL 6 : flash-plugin (RHSA-2017:3222)NessusRed Hat Local Security Checks
critical
104547KB4048951: Security update for Adobe Flash Player (November 2017)NessusWindows : Microsoft Bulletins
critical
104545Adobe Flash Player for Mac <= 27.0.0.183 (APSB17-33)NessusMacOS X Local Security Checks
critical
104544Adobe Flash Player <= 27.0.0.183 (APSB17-33)NessusWindows
critical