CVE-2017-2930
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 25%
from disclosure to weapon0 days
Published on NVDJan 11
1st PoCJan 11
exploitation probability
25%top 2% of all CVEs
observed exploitation
nono source reports it
5 public exploit(s)
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurrency error when manipulating a display list. Successful exploitation could lead to arbitrary code execution.
Affected products
n/a · Adobe Flash Player 24.0.0.186 and earlier.public PoCs found — 5
cve_referencepacketstormsecurity.com/files/140463/Adobe-Flash-24.0.0.186-Code-Execution.htmlunverifiedcve_referencewww.exploit-db.com/exploits/41008/unverifiedcve_referencewww.exploit-db.com/exploits/41012/unverifiedexploitdbwww.exploit-db.com/exploits/41008unverifiedexploitdbwww.exploit-db.com/exploits/41012unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/140463/Adobe-Flash-24.0.0.186-Code-Execution.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0057.htmlhttps://cosig.gouv.qc.ca/en/cosig-2017-01-en/https://helpx.adobe.com/security/products/flash-player/apsb17-02.htmlhttps://security.gentoo.org/glsa/201702-20https://www.exploit-db.com/exploits/41008/https://www.exploit-db.com/exploits/41012/http://www.securityfocus.com/bid/95350http://www.securitytracker.com/id/1037570